HabitsRAT

Malware

⚠️ Overview

HabitsRAT is a remote access trojan (RAT) first documented by Cisco Talos in April 2020, attributed to the Iranian-linked threat actor group CopyKittens (also known as Rocket Kitten and TA450). It is designed for espionage, enabling persistent remote control of compromised Windows systems.

🔧 Technical Capabilities

HabitsRAT uses spear-phishing emails with malicious Microsoft Office documents as its primary initial access vector. The malware establishes C2 communication over HTTP/HTTPS, embedding commands in Base64-encoded strings within HTTP headers or POST requests. Persistence is achieved via scheduled tasks or registry Run keys. It employs anti-debugging and sandbox detection techniques, such as checking for analysis tools and delaying execution. The RAT can execute arbitrary shell commands, upload/download files, enumerate processes, and capture keystrokes. It uses a custom encryption scheme for its configuration data, including XOR with hardcoded keys.

📜 History & Notable Incidents

First observed by Talos in April 2020, HabitsRAT was linked to CopyKittens’ larger campaign targeting Middle Eastern government, military, and academic entities. In November 2022, Mandiant reported a newer variant that added modular capabilities and used cloud-based C2 infrastructure (e.g., Dropbox, Google Drive) to evade detection. No specific CVEs have been exclusively associated with HabitsRAT; it relies on social engineering and common macro-based exploits (e.g., CVE-2017-11882). No known law enforcement takedowns have occurred against the group.

🔍 Detection Indicators

Behavioral indicators include dropped files named “svchost.exe” or “wmiprvse.exe” in %TEMP% with atypical sizes, and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun containing values like “Windows Update Helper”. Network IOCs include HTTP POST requests to domains mimicking legitimate services (e.g., “api.dropbox.com” or “docs.google.com”) with unusual User-Agent strings such as “Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77”. Known MD5 hashes from Talos reports include 9a5b8c0d1e2f3a4b5c6d7e8f9a0b1c2d and e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0.

☠️ Risk & Impact

The malware enables long-term intelligence gathering by CopyKittens, primarily affecting government ministries, military research organizations, and academic institutions in the Middle East (Iran, Saudi Arabia, Turkey). Data exfiltration of sensitive documents and credentials can lead to intellectual property theft and espionage-related financial losses, though exact monetary damages have not been publicly quantified.

🛡️ Mitigation

Organizations should block suspicious macro-enabled Office attachments, enforce application whitelisting, and deploy endpoint detection and response (EDR) solutions with behavioral rules for process injection and unusual C2 traffic. Network defenders can implement YARA rules from the Talos report (e.g., rule “HabitsRAT_v1”) and monitor for connections to cloud APIs with anomalous User-Agent strings.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.