LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0253: RunningRAT

MITRE ATT&CK S0253: RunningRAT Malware details for Windows, with detection guidance, relationships and mapped CVEs.

EnterpriseS0253MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

RunningRAT is a Windows remote access tool documented by ATT&CK from reporting around the 2018 Pyeongchang Winter Olympics. Its ATT&CK relationships matter because they describe a full intrusion-support pattern: persistence through Run keys/startup folders, command execution, discovery, collection of keystrokes and clipboard data, archiving collected data, and attempts to reduce evidence by deleting files or clearing Windows logs.

Executive priority

Treat this as a readiness check for whether Windows endpoint, identity, and SOC controls can prove coverage across credential capture, persistence, data collection, and evidence destruction. The business decision value is not the malware name alone; it is whether incident responders can quickly answer: which users were exposed, what data may have been collected, whether startup persistence exists, and whether logs were tampered with. Because ATT&CK provides no official detection text here, leaders should require evidence from local telemetry and response procedures rather than assume tool-specific coverage.

Technical view

Validate Windows-focused detections and response playbooks against the related ATT&CK behaviors: T1547.001 Registry Run Keys / Startup Folder, T1059.003 Windows Command Shell, T1056.001 Keylogging, T1115 Clipboard Data, T1082 System Information Discovery, T1680 Local Storage Discovery, T1560 Archive Collected Data, T1070.004 File Deletion, T1685 Disable or Modify Tools, and T1685.005 Clear Windows Event Logs. SOC teams should correlate persistence changes, suspicious shell execution, collection staging/archive activity, file deletion, and event log clearing rather than depending on a single malware signature.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry, especially cmd.exe activity
  • Registry modification events for Run keys and startup folder file creation
  • Windows Event Log status and log-clearing events
  • File creation, deletion, and archive/compression activity on endpoints
  • Clipboard and keylogging-related behavioral signals where endpoint tooling supports them

Detection direction

  • Build behavior chains that join persistence, command shell execution, discovery, collection, archiving, and cleanup activity on the same Windows host or user session.
  • Prioritize high-confidence alerts for Windows event log clearing and security-tool impairment, because these behaviors can reduce later forensic visibility.
  • Tune Run key and startup folder monitoring to distinguish authorized software updaters and administration tools from unusual user-context persistence.
  • Review command shell detections for remote or unusual execution context, but avoid assuming every cmd.exe invocation is malicious.
  • Look for collection staging patterns, such as clipboard/keylogging indicators followed by archive creation and file deletion, when telemetry is available.

Mitigation priorities

  • Ensure Windows endpoint logging, EDR/AV, and event forwarding are enabled and protected against tampering.
  • Restrict and monitor persistence locations such as Registry Run keys and startup folders, especially for standard user contexts.
  • Harden administrative privileges so clearing Windows logs or disabling tools requires controlled, auditable access.
  • Maintain incident response procedures for suspected credential capture, including user scoping, password reset decisions, and session/token review where applicable.
  • Use application control or allowlisting where feasible to reduce unauthorized remote access tooling and unexpected command execution.
Additional notes and limits

The supplied ATT&CK object identifies RunningRAT as Windows malware and provides one reporting source plus relationships to multiple techniques. The strongest defensive value comes from those relationships, especially persistence, credential/data collection, command execution, and defense impairment. This take intentionally avoids attribution or current exploitation claims beyond the supplied historical description.

Official ATT&CK detection text is not provided, tactics are not specified on the malware object itself, and no indicators, hashes, command examples, or C2 details were supplied. Coverage decisions require local validation of endpoint telemetry, logging retention, EDR visibility, and authorized administrative behavior.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

RunningRAT

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

10 rows
DomainIDNameRelationship / procedure
EnterpriseT1680Local Storage DiscoveryThis object uses Local Storage Discovery.
EnterpriseT1685Disable or Modify ToolsThis object uses Disable or Modify Tools.
EnterpriseT1059.003Windows Command ShellSub-techniqueThis object uses Windows Command Shell.
EnterpriseT1056.001KeyloggingSub-techniqueThis object uses Keylogging.
EnterpriseT1547.001Registry Run Keys / Startup FolderSub-techniqueThis object uses Registry Run Keys / Startup Folder.
EnterpriseT1070.004File DeletionSub-techniqueThis object uses File Deletion.
EnterpriseT1082System Information DiscoveryThis object uses System Information Discovery.
EnterpriseT1560Archive Collected DataThis object uses Archive Collected Data.
EnterpriseT1685.005Clear Windows Event LogsSub-techniqueThis object uses Clear Windows Event Logs.
EnterpriseT1115Clipboard DataThis object uses Clipboard Data.
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
776e4f1d9f631f39...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle776e4f1d9f63…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  2. [2]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  3. [3]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  4. [4]
    RunningRAT

    (Citation: McAfee Gold Dragon)

  5. [5]
    RunningRAT

    (Citation: McAfee Gold Dragon)

  6. [6]
    RunningRAT

    (Citation: McAfee Gold Dragon)

  7. [7]
    mitre-attackS0253
    Open source URL
  8. [8]
    mitre-attackS0253
    Open source URL
  9. [9]
    mitre-attackS0253
    Open source URL
  10. [10]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  11. [11]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  12. [12]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  13. [13]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  14. [14]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  15. [15]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  16. [16]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  17. [17]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  18. [18]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  19. [19]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  20. [20]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  21. [21]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  22. [22]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  23. [23]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  24. [24]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  25. [25]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  26. [26]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  27. [27]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  28. [28]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  29. [29]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.