StormKittyRAT
Malware⚠️ Overview
StormKittyRAT is a remote access trojan (RAT) first observed in June 2021 by the ASEC analysis team at AhnLab, primarily used by threat actors to steal credentials, cryptocurrency wallets, and sensitive files from Windows systems. It is written in C# and is distributed through phishing emails, fake software cracks, and social engineering campaigns, often marketed on underground forums as a commodity stealer.
🔧 Technical Capabilities
StormKittyRAT employs keylogging, clipboard monitoring, screen capture, and FTP-based exfiltration of saved browser credentials, VPN configurations, and crypto wallet data. It uses a Telegram bot for command-and-control (C2) communication, allowing operators to receive stolen logs in real-time, and can execute remote commands via PowerShell. Persistence is achieved by creating a scheduled task or adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware evades detection by obfuscating its code with Base64 encoding, checking for debugger environments, and terminating if it detects virtual machine or analysis tools like Process Hacker.
📜 History & Notable Incidents
First public analysis of StormKittyRAT occurred in mid-2021 by AhnLab (ASEC), with a later variant emerging in late 2022 that added cryptocurrency wallet targeting across 40+ wallet extensions. No high-profile victims or law enforcement actions have been publicly documented, but it has been linked to campaigns distributing the malware via fake software downloads on YouTube and torrent sites.
🔍 Detection Indicators
Known file hashes include SHA-1 a6f8b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9 (example from AhnLab report). Behavioral indicators include outbound connections over port 443 to Telegram API endpoints (api.telegram.org), creation of scheduled tasks named “WindowsUpdateTask,” and registry modification under the Run key. File artifacts include a dropped executable in %APPDATA%MicrosoftWindowsStart MenuProgramsStartup.
☠️ Risk & Impact
StormKittyRAT primarily causes data theft, including exfiltration of browser-stored credentials, FTP client passwords, and private keys for cryptocurrencies like Bitcoin and Ethereum. The impact is most severe for individual users and small businesses, as stolen credentials can enable account takeover or financial fraud. There are no reports of ransomware or destructive payloads.
🛡️ Mitigation
Organizations should block execution of unknown scripts from email attachments, deploy endpoint detection rules for scheduled task creation and registry Run key modifications, and maintain updated signatures from antivirus vendors such as AhnLab V3 (detected as Trojan/Win32.StormKitty.C53140). Enable PowerShell logging to detect suspicious outbound Telegram API calls.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.