IRRat
Malware⚠️ Overview
IRRat is a remote access trojan (RAT) first documented in June 2021 by researchers at Secureworks, attributed to the Iranian state-sponsored threat group COBALT MIRAGE (also tracked as TA453, APT42, and Phosphorus). It is primarily used for intelligence gathering and surveillance targeting high-value individuals in academia, media, and government sectors.
🔧 Technical Capabilities
IRRat is typically delivered through spear-phishing emails containing malicious LNK files or ISO attachments, which download a .NET-based loader from attacker-controlled infrastructure. The loader installs the RAT, which establishes persistence via registry Run keys and scheduled tasks. IRRat uses HTTPS for command-and-control (C2) communication, often leveraging legitimate cloud services like Dropbox or OneDrive to blend in with normal traffic. It captures keystrokes, steals credentials from browsers, takes screenshots, exfiltrates files, and can execute arbitrary commands. Evasion techniques include code obfuscation, delaying execution to bypass sandboxes, and checking for virtual machine artifacts.
📜 History & Notable Incidents
First reported in June 2021 by Secureworks Counter Threat Unit, IRRat was used in campaigns targeting Iranian diaspora journalists and activists, as well as academics specializing in Middle Eastern affairs. In 2022, Microsoft Threat Intelligence linked similar infrastructure to TA453 operations targeting think tanks and human rights defenders. No public CVEs are directly exploited by IRRat itself, but it often leverages CVE-2022-30190 (Follina) in delivery chains for initial access.
🔍 Detection Indicators
Known file hashes for IRRat samples include SHA256: 5e8a6b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f (example placeholder — verify with Secureworks report). Behavioral indicators include the creation of scheduled tasks named "MicrosoftEdgeUpdateTask" or "AdobeFlashPlayerUpdate". Network IOCs include C2 domains with patterns like *.duckdns.org or *.serveo.net, and User-Agent strings mimicking Chrome 92. Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a key named "WindowsUpdate" pointing to the malware path.
☠️ Risk & Impact
IRRat poses severe risk to targeted individuals and organizations by enabling complete remote control of infected systems, leading to credential theft, exfiltration of sensitive research and communications, and potential secondary deployment of additional malware. The primary affected sectors are academia, media, NGOs, and government agencies focused on Iranian affairs, with data exfiltration supporting Iranian intelligence objectives.
🛡️ Mitigation
Organizations should implement email filtering to block LNK, ISO, and archive attachments, enforce multi-factor authentication, and use endpoint detection and response (EDR) solutions capable of detecting .NET-based RATs via process injection and anomalous network connections. MITRE ATT&CK techniques associated include T1059.001 (PowerShell), T1547.001 (Registry Run Keys), and T1071.001 (Web Protocols).
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.