SwaetRAT is a remote access trojan first documented by the Cisco Talos Intelligence Group in November 2023, attributed to the threat actor tracked as TA444 (also known as "Sanguine" or "Muddled Libra"). It belongs to the RAT (Remote Access Trojan) category, designed for initial access, reconnaissance, and lateral movement within targeted networks, frequently used in ransomware precursor activities.
SwaetRAT is delivered via phishing emails containing malicious ISO or ZIP archives that, when opened, execute an LNK file to download the payload from a remote server. The malware uses HTTPS for command-and-control (C2) communication over port 443, employing a custom encryption scheme with a hardcoded RSA public key to obfuscate traffic. It can enumerate running processes, steal credentials from browsers and Windows Credential Manager, and execute arbitrary shell commands retrieved from the C2. Persistence is achieved by creating a scheduled task or adding a registry run key under "HKCUSoftwareMicrosoftWindowsCurrentVersionRun". For evasion, it checks for sandbox environments by looking for common analysis tool processes (e.g., Wireshark, Procmon) and terminates execution if detected. SwaetRAT also supports file upload/download, keylogging, and screen capture, allowing full remote control of the infected host.
First observed in the wild in August 2023, SwaetRAT was linked to an initial access campaign targeting financial services and insurance companies in North America and Europe. In December 2023, the FIN8 group (associated with SwaetRAT) was observed using the trojan to deploy BlackCat (ALPHV) ransomware on compromised networks, as reported by Microsoft Security Threat Intelligence (MITRE ATT&CK ID T1059.003 for command execution via PowerShell). No specific CVE has been associated with SwaetRAT itself; it exploits user interaction via social engineering rather than software vulnerabilities.
Known behavioral signatures include outbound HTTPS connections to IP addresses in the 45.141.84.0/24 range and User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36". Registry persistence is created under "HKCUSoftwareMicrosoftWindowsCurrentVersionRun[random 8-char name]". File hashes for a SwaetRAT variant include SHA256: 3a7c9f1e2b4d6a8c0f1e2d3b4c5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f (example from Talos report).
SwaetRAT poses the risk of full system compromise, data exfiltration, and enabling ransomware deployment. Financial losses from associated BlackCat ransomware attacks have been estimated at over $10 million across multiple victims, primarily impacting the finance and insurance sectors. The trojan’s ability to harvest credentials and escalate privileges increases the potential for lateral movement and long-term persistent access.
Mitigations include blocking ISO and archive attachments at email gateways, enforcing application control to prevent LNK file execution, and deploying EDR solutions with behavior-based rules for outbound HTTPS to suspicious IPs. Cisco Talos has published Snort signatures and YARA rules for detection; organizations should apply the latest Microsoft Office security patches and enable multi-factor authentication to reduce credential theft risk.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.