Skip to content
DnsLister Forum

Where domain hunters compare notes

RatonRAT: A .NET RAT Targeting Windows Credentials and Systems

What is RatonRAT?

RatonRAT is a .NET-based Remote Access Trojan targeting Windows systems. It supports credential theft, screen capture, system discovery, persistence, and C2 communication.

Key Features

  • Credential & Data Theft: Steals credentials and collects system and hardware information.
  • Persistence: Uses scheduled tasks and Active Setup to maintain execution after user logon.
  • Defense Evasion: Bypasses PowerShell ExecutionPolicy and adds its process to Microsoft Defender exclusions.
  • System & VM Discovery: Checks running processes, privileges, BIOS and disk information, plus VirtualBox and VMware environments.
  • C2 Communication: Connects to a configured C2 server to receive further instructions.
  • Configurable .NET Malware: Uses a configurable .NET architecture and Costura/Fody to bundle components.

How to detect and reduce exposure: https://any.run/malware-trends/raton/

https://i.redd.it/h51ni0eg92rh1.png

Source: r/ANYRUN · by /u/ANYRUN-team

Leave a Reply

Your email address will not be published. Required fields are marked *