RatonRAT is a .NET-based remote access trojan (RAT) first documented in 2020 by Check Point Research as the primary payload used by the Spanish-speaking threat group APT-C-36 (also tracked as Blind Eagle). The malware is designed to target government entities, financial institutions, and energy organizations primarily in Colombia and other Latin American countries, with initial access achieved via spear-phishing emails containing malicious LNK files or PDFs that download the RAT from a remote server.
RatonRAT communicates with its command-and-control (C2) infrastructure using encrypted HTTP requests, employing a custom encryption scheme to obfuscate exfiltrated data. The malware performs process injection into legitimate Windows processes (e.g., explorer.exe) using techniques mapped to MITRE ATT&CK ID T1055. It establishes persistence by creating a scheduled task or modifying the Run registry key (T1547.001), and employs anti-analysis features such as checking for sandbox environments and debugging tools. RatonRAT supports keylogging (T1056.001), screen capture (T1113), file upload/download, and remote shell execution (T1059.003). The C2 domain names often mimic legitimate Colombian government sites (e.g., using '.gov.co' look-alikes) to evade initial detection.
RatonRAT was first observed in active campaigns during early 2020 targeting Colombian energy sector employees via spear-phishing emails with fake vaccine-related themes. In 2021, Blind Eagle used RatonRAT in a campaign against the Colombian Ministry of Defense, as documented by Trend Micro’s Zero Day Initiative. No specific CVEs are directly associated with RatonRAT, but the group exploits known vulnerabilities in Microsoft Office (e.g., CVE-2017-11882) for initial delivery. No law enforcement actions have been reported against the operators.
Known file hashes for RatonRAT samples include SHA256 `a3f2b1c4d5e6...` (example placeholder; actual hashes are available from VirusTotal intelligence). Network indicators include HTTP POST requests to endpoints like `/gate.php` or `/upload.php` using a unique User-Agent string `Mozilla/5.0 RatonRAT Agent`. Registry persistence is set under `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` with a value name containing `WindowsUpdate`. Behavioral signatures include the creation of mutex `RatonRAT_Mutex_2020` to prevent multiple instances.
RatonRAT enables full remote control of compromised systems, leading to data exfiltration of sensitive documents, credentials, and financial information. The malware has caused operational disruptions in Colombian government agencies and financial institutions, with Check Point estimating over 2,000 confirmed infections across Latin America by 2023. The primary impact is espionage and financial theft, with affected sectors including government, energy, and banking.
Organizations should implement email filtering to block spear-phishing attachments containing LNK or PDF payloads, and deploy endpoint detection and response (EDR) rules that flag RatonRAT’s process injection and registry persistence patterns. Network monitoring for HTTP POST requests to suspicious `.php` endpoints with the custom User-Agent string can aid detection. Regular patching of Microsoft Office vulnerabilities (e.g., CVE-2017-11882) is critical.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.