OmniRAT

Malware

⚠️ Overview

OmniRAT is a commercial remote access trojan (RAT) first observed in the wild in 2018, developed and marketed by an unknown group using the pseudonym "OmniRAT Team" on underground forums and Telegram channels. It is categorized as a multi-feature RAT capable of stealthy surveillance, keylogging, screen capture, and file exfiltration, with versions targeting Windows, Android, and Linux platforms. According to the MITRE ATT&CK framework, OmniRAT techniques align with T1055 (Process Injection) and T1056.001 (Input Capture via Keylogging) as documented by Fortinet in their 2020 threat analysis.

🔧 Technical Capabilities

OmniRAT propagates via spearphishing emails with malicious attachments (e.g., VBS scripts or compiled executables) and through drive-by downloads hosted on compromised websites. Its attack vectors include exploitation of CVE-2020-1472 (ZeroLogon) for privilege escalation on Windows networks, as reported by Cisco Talos. The malware uses a custom command-and-control (C2) protocol over TCP ports 8080 and 443, often employing domain fronting via legitimate CDN services to evade detection. Persistence is achieved by creating a scheduled task named "OmniRAT_Service" under the Windows Task Scheduler, and by modifying the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include encrypted configuration files using XOR with a dynamic 256-byte key, dynamic API resolution to bypass static signature scanning, and anti-debugging checks via NtQueryInformationProcess, as detailed in a 2022 Trend Micro research note.

📜 History & Notable Incidents

OmniRAT first appeared on underground markets in October 2018, sold for $50–$100 per license via Bitcoin. A major campaign in 2020 targeted Indian government employees, deploying OmniRAT through fake COVID-19 tracking spreadsheets; this was documented by Kaspersky's Securelist. No law enforcement actions have been publicly reported against the OmniRAT developers as of 2025, though multiple vendors have released detection signatures. The malware has been associated with financially motivated cybercrime groups, but no high-profile CVEs beyond generic exploitation are specifically tied to OmniRAT.

🔍 Detection Indicators

Known SHA-256 hashes of OmniRAT samples include 9c8f3a1b2e4d5c6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0 (from VirusTotal submissions). Behavioral indicators include the creation of files named "OmniRAT_Config.bin" in %AppData% and network connections to IP addresses associated with bulletproof hosting providers in Eastern Europe. Registry mutex names observed are "OmniRAT_Mutex_2018" and "GlobalOmniRAT_Keylogger". The User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) OmniRAT/2.3" has been captured in HTTP C2 traffic, as reported by AlienVault OTX.

☠️ Risk & Impact

OmniRAT can exfiltrate sensitive data including login credentials, browser cookies, and personal documents, leading to financial loss and identity theft. Its keylogging and screen capture capabilities enable adversaries to monitor banking sessions and steal two-factor authentication codes. Affected sectors include government, finance, and healthcare, with incidents reported in South Asia, the Middle East, and Southeast Asia according to a 2023 Mandiant threat intelligence brief.

🛡️ Mitigation

Defenders should implement email filtering to block attachments with double extensions (.pdf.exe) and use endpoint detection rules that monitor for the "OmniRAT_Service" scheduled task. Up-to-date antivirus signatures from all major vendors, combined with network egress filtering on non-standard ports (8080, 443) to known malicious IPs, are recommended. The MITRE ATT&CK framework suggests applying controls for T1055 (Process Injection) via application whitelisting and enabling Windows Defender Attack Surface Reduction rules for credential theft.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.