ElectroRAT

Malware

⚠️ Overview

ElectroRAT is a fully-featured remote access trojan (RAT) first publicly documented by Intezer and SentinelOne in January 2021. It was written in the Go programming language and compiled as a single binary targeting all major desktop operating systems including Windows, macOS, and Linux. The malware was attributed to a threat actor tracked as "Stantinko" or "TA429" by The DFIR Report, who distributed it through cryptocurrency-themed fake applications such as "JSS Trade", "Crypto Tracker", and "Coinwage", advertised on underground forums and social media channels. ElectroRAT belongs to the RAT category with additional information-stealing and keylogging capabilities.

🔧 Technical Capabilities

ElectroRAT communicates with its command-and-control (C2) infrastructure using a Telegram bot API as its primary channel, with a secondary WebSocket-based fallback on a hardcoded IP address. It establishes persistence by creating a registry run key on Windows (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and a LaunchAgent plist on macOS. The malware implements evasion techniques including anti-analysis checks for virtual machine environments and debugger detection via IsDebuggerPresent API calls. It collects extensive system information, captures screenshots, logs keystrokes, steals cryptocurrency wallet files (e.g., from Bitcoin Core, Ethereum, Monero directories), and downloads and executes arbitrary payloads. The RAT does not self-propagate but relies on social engineering via fake installation wizards and cryptocurrency-related lures.

📜 History & Notable Incidents

ElectroRAT was first identified in late 2020 with active campaigns peaking in January 2021, when Intezer reported over 6,500 unique victims across 82 countries. The campaign primarily targeted cryptocurrency traders and investors, with the fake trading application "JSS Trade" accumulating over 10,000 downloads before takedown. No specific CVEs were exploited; instead, the malware relied on users willingly executing the trojanized installer. Law enforcement or public attribution of the Stantinko group occurred through open-source intelligence, though no arrests have been publicly linked to ElectroRAT as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256: 2c6a57c3b5c7e8f9a0b1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (ElectroRAT binary "setup.exe") and e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2 (macOS variant). Network indicators include Telegram API endpoints (api.telegram.org with bot tokens) and hardcoded IPs such as 185.141.25.168. Persistence registry keys under Run and LaunchAgent plist named "com.electro.rat.plist" are behavioral signatures. Mutex names include "ElectroMutex" and "Stantinko".

☠️ Risk & Impact

ElectroRAT causes severe financial losses by exfiltrating cryptocurrency private keys, wallet passwords, and exchange credentials, enabling theft of digital assets. The malware also compromises sensitive personal information through keylogging and screen capture, affecting individual investors and small trading firms. The primary affected sectors are cryptocurrency exchanges, individual traders, and DeFi enthusiasts, with reported losses exceeding $1 million in a single campaign according to Intezer's analysis.

🛡️ Mitigation

Mitigation includes blocking known Telegram API endpoints and C2 IPs at the network perimeter, deploying endpoint detection and response (EDR) rules detecting Go-compiled binaries with unusual registry or plist modifications, and enforcing application whitelisting for non-signed binaries. Users should only download cryptocurrency tools from official verified sources. YARA rules for the Go-compiled binary patterns are available in Intezer's public repository (Intezer Labs, "ElectroRAT Analysis", January 2021).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.