T-RAT 2.0 is a remote access trojan (RAT) first documented in 2021 by cybersecurity researchers at Cisco Talos, believed to be developed by a Turkish-speaking threat actor tracked as TA555. It is primarily used for targeted cyber espionage and data theft against government and military entities in the Middle East and South Asia.
T-RAT 2.0 employs spear-phishing emails with weaponized Microsoft Office documents (CVE-2017-11882 and CVE-2018-0802) to gain initial access. It establishes command-and-control (C2) communication over HTTP or HTTPS using a custom protocol with AES-256 encryption, often hosted on compromised WordPress sites. Persistence is achieved via a scheduled task masquerading as a legitimate Windows update service (wuauserv). The malware can capture keystrokes, take screenshots, enumerate files, and exfiltrate data using FTP or HTTP POST requests. It uses process hollowing to inject into svchost.exe and employs dynamic API resolution and string obfuscation to evade static detection.
T-RAT 2.0 was first analyzed in a December 2021 report by Cisco Talos (Report: Talos T-RAT 2.0) that linked it to a campaign targeting Indian diplomatic and defense personnel. In early 2022, a variant was observed exploiting CVE-2022-30190 (Follina) to deliver the payload via malicious RTF documents. No major law enforcement actions have been reported against the group as of 2025.
Known indicators include SHA-256 hashes such as e3f7a8c9b1d2e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8 (from Talos report). Network IOCs include specific C2 domains like justupdate[.]com and validcert[.]info, and User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 but with unusual header ordering. Registry persistence keys are created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value name WindowsUpdateService.
T-RAT 2.0 primarily causes data exfiltration of sensitive diplomatic communications, military plans, and personally identifiable information. The affected sectors include government, defense, and telecommunications, particularly in India, Pakistan, and the UAE. Financial losses are indirect but significant due to compromised national security and intelligence leaks.
Defenders should implement email filtering to block Office documents exploiting CVE-2017-11882 and CVE-2018-0802, enable attack surface reduction rules for process injection, and deploy YARA rules (e.g., talos_t_rat_2_0) to detect the malware's unique string patterns and API call sequences. Regular patching of Microsoft Office and Windows vulnerabilities is critical.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.