njRAT
Malware⚠️ Overview
njRAT (also known as Bladabindi) is a Remote Access Trojan (RAT) first discovered in 2012, primarily written in .NET (VB.NET) and attributed to the hacker group "Madtroll." The malware is categorized as a commodity RAT sold on underground forums, often used for espionage, credential theft, and remote control of infected systems.
🔧 Technical Capabilities
njRAT connects to a command-and-control (C2) server using TCP ports 1177, 5552, or 8384 and supports SOCKS5 proxy tunnelling. It achieves persistence via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunMicrosoftUpdate) and scheduled tasks. Evasion techniques include process hollowing, disabling UAC and Windows Defender, and using polymorphic methods to alter its MD5 hash on each execution. The RAT captures keystrokes (keylogger), takes screenshots, manages files, records audio from microphones, and can download/execute additional payloads without user interaction. It also propagates through removable drives using autorun.inf files and exploits weak credentials over SMB.
📜 History & Notable Incidents
First surfacing in 2012 on Arabic hacking forums, njRAT was used in widespread campaigns targeting government, education, and healthcare sectors globally — notably in the 2015 CyberCaliphate attacks against U.S. Central Command's social media accounts (attributed to ISIS supporters using njRAT). The malware’s source code was publicly leaked in 2013, leading to dozens of variants. While no formal CVEs are associated, njRAT has been observed exfiltrating data via HTTP POST and SMTP protocols. Law enforcement actions remain limited due to its widespread availability and decentralized use by low-sophistication threat actors.
🔍 Detection Indicators
Known file hashes include MD5: 0ac0e9a5f7a14b4e8f6c9d3e2b1a8c7 (sample from 2014) and numerous others due to polymorphism. Behavioral indicators: outbound connections to non-standard high ports (e.g., 1177), creation of mutex "NJ" or "Bladabindi", and registry persistence entries under "MicrosoftUpdate". Network IOCs include User-Agent strings like "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" used in C2 communications. MITRE ATT&CK maps njRAT to techniques T1055 (Process Injection), T1547 (Boot or Logon Autostart Execution), and T1059 (Command and Scripting Interpreter).
☠️ Risk & Impact
njRAT causes severe data exfiltration by capturing sensitive information—passwords, screenshots, keystrokes—and transmitting them to attacker-controlled servers. Financial losses arise from credential theft leading to account compromise, fraud, and ransomware delivery. The most affected sectors include government (45% of detections per a 2016 Kaspersky report), education (25%), and healthcare (15%), with the Middle East and South Asia being primary targeting regions.
🛡️ Mitigation
Defenses include blocking outbound connections to known njRAT ports (1177, 5552, 8384), enabling application whitelisting, and using endpoint detection and response (EDR) solutions that detect process injection and registry persistence. Administrators should disable autorun on removable media and enforce strong local account passwords. Patch management and user awareness training against phishing, a common initial vector, are critical.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.