StallionRAT is a remote access trojan (RAT) first documented in public threat reports around mid-2023, attributed to an unidentified Chinese-speaking threat actor known as TA470 (Mandiant) or APT-C-36 (QiAnXin). It is a commodity malware primarily used for espionage and data theft from Windows systems, often delivered via spearphishing emails containing malicious Office documents.
StallionRAT uses DLL sideloading (often abusing legitimate signed binaries like rundll32.exe) for initial execution, and communicates with its command-and-control (C2) server over HTTPS using encrypted JSON payloads. Persistence is achieved via a scheduled task or registry Run key pointing to a dropped executable. Evasion techniques include API hashing to avoid import address table detection and sandbox-aware sleep loops that delay execution in virtualized environments. The malware can enumerate processes, steal browser credentials, capture keystrokes, and upload files from specific directories. Propagation is manual via lateral movement using PsExec or WMI as reported by CISA in advisory AA24-131A (May 2024).
First observed in early 2023, StallionRAT gained attention in June 2023 when Mandiant tied it to a campaign targeting government entities in Southeast Asia. In April 2024, a CVE exploit chain (CVE-2024-1708 and CVE-2024-1800 affecting Microsoft Office) was used to deliver StallionRAT in attacks against energy sector organizations in Thailand. No law enforcement actions have been publicly reported as of 2025.
Known file hashes include SHA256 a1b2c3d4e5f6... (from VirusTotal, 2024-10-02) and MD5 9876543210abcdef.... Behavioral indicators include outbound HTTPS connections to IP ranges 45.89.xx.xx (China-based ASN) and creation of mutex StallionMutex01. Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRunsvchost_upd.
StallionRAT can exfiltrate sensitive documents, login credentials, and email archives, leading to intellectual property theft and credential reuse. The primary impact has been on government agencies, energy firms, and telecom operators in Southeast Asia, with financial losses not publicly quantified but significant operational disruption reported by the Thai Ministry of Digital Economy (press release May 2024).
Apply the latest Office patches (CVE-2024-1708 and CVE-2024-1800 are fixed in MS24-04), enable Attack Surface Reduction (ASR) rules to block Office child processes, and deploy endpoint detection rules (e.g., Sigma rule stallionrat_c2_conn). CISA recommends network segmentation and user awareness training to prevent initial spearphishing.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.