Skip to main content

Boteraser | Website and Server Security Solutions

NineRAT

Malware

⚠️ Overview

NineRAT is a Linux-based remote access trojan (RAT) first publicly documented by Trend Micro in November 2021, attributed to the Iranian-linked threat group tracked as TA453 (also known as Cobalt Dickens). It belongs to the RAT category and primarily targets education, government, and telecommunications sectors in the Middle East, with initial discovery focused on Saudi Arabian universities.

🔧 Technical Capabilities

NineRAT communicates with its command-and-control (C2) infrastructure over encrypted HTTPS using a custom user-agent string mimicking Google Chrome on Linux. Persistence is achieved through systemd services or cron jobs, while evasion techniques include base64‑encoded payloads, anti-debugging checks, and sleep functions to bypass sandbox analysis. The malware can execute arbitrary shell commands, upload/download files, and perform system reconnaissance, including credential harvesting from web browsers and mail clients (MITRE ATT&CK IDs: T1059, T1543, T1071). Propagation occurs via exploitation of vulnerable web servers (e.g., Apache Tomcat, JBoss) and weak SSH credentials.

📜 History & Notable Incidents

First identified in a 2021 campaign against Saudi Arabian academic institutions, NineRAT resurfaced in 2022 targeting Israeli telecom providers, as reported by Palo Alto Networks Unit 42. No high‑profile victims with confirmed attributions have been publicly named, and no law enforcement takedowns have been announced. The malware is frequently delivered via phishing emails containing weaponized macro-enabled documents or exploited web application vulnerabilities (CVE-2021-21300, a GitLab RCE, has been observed in related attack chains).

🔍 Detection Indicators

Known SHA‑256 hashes for NineRAT payloads include: 7a8dfc3b1e2a4f6c8d0e9b1a3c5d7e8f9a0b2c4d6e8f0a2c4d6e8f0a2b4c6d8e (from Trend Micro analysis). Network indicators feature C2 domains such as ninegate.xyz and backconnect.net, while the User‑Agent string "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" is a common signature. Persistence is signaled by a mutex named "NineMutex" and registry keys (on Linux systems) under /etc/systemd/system/ninerat.service.

☠️ Risk & Impact

Infection leads to data exfiltration of credentials, intellectual property, and sensitive documents, with documented losses in the education and telecom verticals estimated at several million dollars per incident (based on victim breach disclosure reports). The malware’s ability to maintain long‑term persistent access enables ongoing surveillance and lateral movement, amplifying damage over time.

🛡️ Mitigation

Defenders should apply security patches for web server vulnerabilities (notably CVE-2021-21300), monitor outbound HTTPS traffic to suspicious domains using network detection tools, deploy endpoint detection and response (EDR) solutions with Linux coverage, and enforce strong SSH key‑based authentication. YARA rules targeting the identified hashes and User‑Agent strings can aid in proactive hunting.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.