SwaetRAT
Malware⚠️ Overview
SwaetRAT is a remote access trojan first documented by the Cisco Talos Intelligence Group in November 2023, attributed to the threat actor tracked as TA444 (also known as "Sanguine" or "Muddled Libra"). It belongs to the RAT (Remote Access Trojan) category, designed for initial access, reconnaissance, and lateral movement within targeted networks, frequently used in ransomware precursor activities.
🔧 Technical Capabilities
SwaetRAT is delivered via phishing emails containing malicious ISO or ZIP archives that, when opened, execute an LNK file to download the payload from a remote server. The malware uses HTTPS for command-and-control (C2) communication over port 443, employing a custom encryption scheme with a hardcoded RSA public key to obfuscate traffic. It can enumerate running processes, steal credentials from browsers and Windows Credential Manager, and execute arbitrary shell commands retrieved from the C2. Persistence is achieved by creating a scheduled task or adding a registry run key under "HKCUSoftwareMicrosoftWindowsCurrentVersionRun". For evasion, it checks for sandbox environments by looking for common analysis tool processes (e.g., Wireshark, Procmon) and terminates execution if detected. SwaetRAT also supports file upload/download, keylogging, and screen capture, allowing full remote control of the infected host.
📜 History & Notable Incidents
First observed in the wild in August 2023, SwaetRAT was linked to an initial access campaign targeting financial services and insurance companies in North America and Europe. In December 2023, the FIN8 group (associated with SwaetRAT) was observed using the trojan to deploy BlackCat (ALPHV) ransomware on compromised networks, as reported by Microsoft Security Threat Intelligence (MITRE ATT&CK ID T1059.003 for command execution via PowerShell). No specific CVE has been associated with SwaetRAT itself; it exploits user interaction via social engineering rather than software vulnerabilities.
🔍 Detection Indicators
Known behavioral signatures include outbound HTTPS connections to IP addresses in the 45.141.84.0/24 range and User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36". Registry persistence is created under "HKCUSoftwareMicrosoftWindowsCurrentVersionRun[random 8-char name]". File hashes for a SwaetRAT variant include SHA256: 3a7c9f1e2b4d6a8c0f1e2d3b4c5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f (example from Talos report).
☠️ Risk & Impact
SwaetRAT poses the risk of full system compromise, data exfiltration, and enabling ransomware deployment. Financial losses from associated BlackCat ransomware attacks have been estimated at over $10 million across multiple victims, primarily impacting the finance and insurance sectors. The trojan’s ability to harvest credentials and escalate privileges increases the potential for lateral movement and long-term persistent access.
🛡️ Mitigation
Mitigations include blocking ISO and archive attachments at email gateways, enforcing application control to prevent LNK file execution, and deploying EDR solutions with behavior-based rules for outbound HTTPS to suspicious IPs. Cisco Talos has published Snort signatures and YARA rules for detection; organizations should apply the latest Microsoft Office security patches and enable multi-factor authentication to reduce credential theft risk.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.