YaRAT
Malware⚠️ Overview
YaRAT (also styled YARAT) is a remote access trojan (RAT) first publicly documented by Palo Alto Networks Unit 42 in 2017, attributed with moderate confidence to the Iranian threat group APT33 (also known as Elfin, Magnallium). The malware is a custom Delphi-coded backdoor used primarily for cyber espionage against targets in the aerospace, energy, and defense sectors, and falls under the RAT category.
🔧 Technical Capabilities
YaRAT communicates with its command-and-control (C2) infrastructure over HTTP using custom encryption methods, including XOR with a hardcoded key. It achieves persistence by creating a scheduled task or adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value pointing to the malicious binary. The malware employs process hollowing to inject into legitimate processes (e.g., svchost.exe) for evasion, and uses API hooking to intercept network traffic. It can execute arbitrary shell commands, enumerate files and directories, upload/download files, take screenshots, and log keystrokes. Evasion techniques include string obfuscation and checking for sandbox environments by detecting analysis tools like Wireshark or VMWare.
📜 History & Notable Incidents
First observed in early 2017 targeting Saudi Arabian government and energy entities, YaRAT was used in a campaign that leveraged spear-phishing emails with malicious Excel payloads (CVE-2017-0199). In 2018, Unit 42 reported that APT33 used YaRAT alongside the destructive wiper Shamoon 2.0, indicating a dual purpose of espionage and sabotage. No public law enforcement actions have been documented; however, the group remains active as of 2023 according to Mandiant's M-Trends report.
🔍 Detection Indicators
Known file hashes include SHA256 a3f1c4e5b6d7... (example from Unit 42 report), and the mutex name GlobalYARAT_Installed is a common artifact. Network indicators include HTTP POST requests to C2 domains using a User-Agent string mimicking Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0). Registry keys HKCUSoftwareYARAT store configuration data.
☠️ Risk & Impact
YaRAT facilitates full remote control of infected systems, leading to credential theft, intellectual property exfiltration, and deployment of additional payloads. Targeted sectors include aerospace (e.g., Saudi Arabian airlines) and energy (oil and gas firms), with potential financial losses from operational disruption and data theft. The malware's integration with destructive wipers elevates long-term risk to critical infrastructure.
🛡️ Mitigation
Mitigate YaRAT by enforcing application whitelisting and disabling macro execution in Microsoft Office; deploy network detection rules for HTTP C2 patterns, and use endpoint detection and response (EDR) tools to monitor for YARAT-specific process injection and mutex creation. Patch CVE-2017-0199 and maintain updated signatures from vendor feeds.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.