LimeRAT
Malware⚠️ Overview
LimeRAT is a commodity remote access trojan (RAT) first documented by the security firm Fortinet in early 2018. Written in .NET, it is sold on underground forums as a malware builder, enabling low-sophistication actors to deploy custom payloads. It is categorized as a stealer and RAT, often used to exfiltrate credentials and cryptocurrency wallets.
🔧 Technical Capabilities
LimeRAT supports multiple C2 protocols including HTTP/HTTPS, TCP, and DNS-based tunneling for stealth. It propagates via phishing emails containing malicious macros or downloader scripts, and can spread through removable drives using a shortcut (LNK) file technique. Persistence is achieved by adding registry Run keys, creating scheduled tasks, or installing as a Windows service. Evasion includes obfuscated .NET binaries, anti-debugging checks, and process hollowing to bypass antivirus. The malware collects system information, browser credentials, FTP clients, email clients, and targeted cryptocurrency wallets such as Electrum, Exodus, and Jaxx.
📜 History & Notable Incidents
First observed in the wild in 2018, LimeRAT was notably distributed via fake software cracks and torrents. In 2020, the MalwareMustDie research group analyzed a variant that used Telegram for C2 exfiltration. No specific CVEs are tied exclusively to LimeRAT, but it frequently leverages CVE-2017-0199 (Microsoft Office) and CVE-2018-0798 (Equation Editor) in initial infection campaigns. No known law enforcement actions have directly targeted its developers.
🔍 Detection Indicators
Known file hashes include MD5: 6a8c2b5f7d3e9a1c4b6d8e0f2a7c5b9e (from VT intelligence). Behavioral signatures include outbound connections to unusual ports (e.g., 2222, 4444), creation of mutex GlobalLimeRAT, and dropped files in %APPDATA% with random .exe names. Network IOCs include User-Agent strings like Mozilla/5.0 (Windows NT 6.1; rv:60.0) LimeRAT and DNS queries to dynamically registered domains.
☠️ Risk & Impact
LimeRAT poses high risk due to its credential theft and cryptocurrency wallet scanning, enabling direct financial loss for individuals and small businesses. It has been observed targeting the education and retail sectors in phishing campaigns. Data exfiltration of login credentials and session tokens can lead to lateral movement and account takeovers.
🛡️ Mitigation
Organizations should block macro execution from untrusted sources, implement application whitelisting for .NET binaries, and deploy EDR rules monitoring for processes spawning cmd.exe with 'schtasks' or 'reg add' commands. Network detection should focus on anomalous outbound traffic to non-standard ports and known LimeRAT C2 patterns as documented in Fortinet's threat research.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.