LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0385: njRAT

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.[1]

EnterpriseS0385MalwareObject v1.7Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

njRAT is a Windows remote access tool documented by ATT&CK as first observed in 2012 and used by multiple campaigns and groups. Its business significance is not the tool name alone; it represents commodity remote access capability that can support hands-on-keyboard activity, discovery, credential collection through keylogging, data collection, exfiltration over command-and-control, and cleanup. For leaders, this is a useful test case for whether endpoint, network, identity, and incident response teams can recognize and contain common RAT behavior rather than relying only on malware signatures.

Executive priority

Prioritize njRAT as a resilience and readiness validation scenario for Windows environments, especially where phishing-led commodity malware could disrupt sensitive operations or enable data theft. The ATT&CK relationships connect this software to government, energy, manufacturing, aviation, aerospace, transportation, defense, telecommunications, technology, finance, education, retail, and research targeting contexts through associated groups and campaigns, but local exposure must be determined from your own environment. Executives should ask whether the organization can prove collection of Windows endpoint telemetry, command-line activity, PowerShell activity, RDP usage, outbound C2-like traffic, and data movement evidence needed for investigation and compliance reporting.

Technical view

ATT&CK does not provide a specific detection analytic for njRAT, so defenders should validate coverage against its mapped behaviors: Windows command shell and PowerShell execution, registry queries, process/window/user/remote-system discovery, local data collection, keylogging indications, RDP use, encoded or compiled-after-delivery artifacts, file deletion, persistence cleanup, and exfiltration over an existing C2 channel. Because the malware object platform is Windows, prioritize Windows endpoint and identity telemetry even though some related ATT&CK techniques are broader. Relationship context shows njRAT is used by multiple groups and Operation Spalax, making behavior-based detection more durable than actor-specific assumptions.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • PowerShell execution logs and script block/module logging where available
  • Windows Registry query and modification evidence
  • File creation, deletion, and suspicious temporary/staging file activity
  • Endpoint alerts or behavioral traces associated with keylogging or input capture

Detection direction

  • Do not depend only on a malware family signature; tune detections around the mapped ATT&CK behaviors used by njRAT.
  • Correlate command shell or PowerShell activity with discovery commands, registry queries, process enumeration, and unusual outbound connections from the same Windows host.
  • Review RDP activity in context: distinguish expected administrative access from new, unusual, or post-compromise interactive sessions.
  • Look for evidence of data staging and exfiltration over an established command-and-control channel, especially when local file access precedes sustained outbound traffic.
  • Account for false positives from legitimate administration tools, software inventory, help desk activity, and endpoint management scripts by baselining approved behavior.

Mitigation priorities

  • Ensure Windows endpoints have monitored endpoint protection and centralized logging sufficient for process, PowerShell, registry, file, and network investigation.
  • Restrict and monitor script and command interpreter abuse, especially PowerShell and Windows command shell activity that is not part of approved administration.
  • Harden identity and remote access controls around RDP, including least privilege, strong authentication, and review of exposed or unnecessary remote access paths.
  • Maintain egress monitoring and filtering so unusual outbound command-and-control or exfiltration behavior can be investigated quickly.
  • Prepare IR playbooks for commodity RAT containment: isolate host, preserve volatile and endpoint evidence, review credentials used on the host, and scope lateral movement.
Additional notes and limits

The strongest decision value is to use njRAT as a behavior-based readiness scenario for Windows RAT activity. ATT&CK links it to Operation Spalax and several groups, and maps it to discovery, execution, collection, credential access, lateral movement, exfiltration, and stealth-related techniques. External references also note naming and variant ambiguity around Bladabindi, LV, and Njw0rm, including differing treatment of removable-media spreading in some sources; defenders should verify which indicators or behaviors apply before merging them into detections.

The supplied ATT&CK object has no official detection text, no aliases listed in the main object fields, no labels, and no object-level tactics specified. The official platform is Windows; broader platform lists appear in related technique descriptions and should not be treated as confirmed njRAT platforms. This take does not assert current exploitation, customer exposure, attribution, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

njRAT

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

31 rows
DomainIDNameRelationship / procedure
EnterpriseT1082System Information Discovery

njRAT enumerates the victim operating system and computer name during the initial infection.[1]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

njRAT has a module that steals passwords saved in victim web browsers.[1][5][6]

EnterpriseT1010Application Window Discovery

njRAT gathers information about opened windows during the initial infection.[1]

EnterpriseT1105Ingress Tool Transfer

njRAT can download files to the victim’s machine.[1][5] APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies.[2]

EnterpriseT1083File and Directory Discovery

njRAT can browse file systems using a file manager module.[1]

EnterpriseT1012Query Registry

njRAT can read specific registry values.[5]

EnterpriseT1120Peripheral Device Discovery

njRAT will attempt to detect if the victim system has a camera during the initial infection. njRAT can also detect any removable drives connected to the system.[1][5]

EnterpriseT1125Video Capture

njRAT can access the victim's webcam.[1][6]

EnterpriseT1113Screen Capture

njRAT can capture screenshots of the victim’s machines.[5][2]

EnterpriseT1106Native API

njRAT has used the ShellExecute() function within a script.[5]

EnterpriseT1018Remote System Discovery

njRAT can identify remote hosts on connected networks.[1]

EnterpriseT1070.004File DeletionSub-technique

njRAT is capable of deleting files.[1][5]

EnterpriseT1059.001PowerShellSub-technique

njRAT has executed PowerShell commands via auto-run registry key persistence.[5]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

njRAT has included a base64 encoded executable.[5]

EnterpriseT1132.001Standard EncodingSub-technique

njRAT uses Base64 encoding for C2 traffic.[1]

EnterpriseT1027.004Compile After DeliverySub-technique

njRAT has used AutoIt to compile the payload and main script into a single executable after delivery.[5]

EnterpriseT1571Non-Standard Port

njRAT has used port 1177 for HTTP C2 communications.[5]

EnterpriseT1091Replication Through Removable Media

njRAT can be configured to spread via removable drives.[1][5]

EnterpriseT1033System Owner/User Discovery

njRAT enumerates the current user during the initial infection.[1]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

njRAT has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\ and dropped a shortcut in %STARTUP%.[1][5]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

njRAT has a module for performing remote desktop access.[1][2]

EnterpriseT1056.001KeyloggingSub-technique

njRAT is capable of logging keystrokes.[1][5][6][2]

EnterpriseT1071.001Web ProtocolsSub-technique

njRAT has used HTTP for C2 communications.[5]

EnterpriseT1686.003Windows Host FirewallSub-technique

njRAT has modified the Windows firewall to allow itself to communicate through the firewall.[1][5]

EnterpriseT1070.009Clear PersistenceSub-technique

njRAT is capable of manipulating and deleting registry keys, including those used for persistence.[5]

EnterpriseT1112Modify Registry

njRAT can create, delete, or modify a specified Registry key or value.[1][5]

EnterpriseT1041Exfiltration Over C2 Channel

njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information.[5][2]

EnterpriseT1057Process Discovery

njRAT can search a list of running processes for Tr.exe.[5]

EnterpriseT1568.001Fast Flux DNSSub-technique

njRAT has used a fast flux DNS for C2 IP resolution.[5]

EnterpriseT1059.003Windows Command ShellSub-technique

njRAT can launch a command shell interface for executing commands.[1]

EnterpriseT1005Data from Local System

njRAT can collect data from a local system.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0099: APT-C-36

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.[1][2][3][4]

GroupEnterprise

G0043: Group5

Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes. Group5 has used two commonly available remote access tools (RATs), njRAT and NanoCore, as well as an Android RAT, DroidJack. [1]

GroupEnterprise

G0143: Aquatic Panda

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.[1]

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0078: Gorgon Group

Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States. [1]

GroupEnterprise

G1018: TA2541

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.[1][2]

CampaignEnterprise

C0005: Operation Spalax

Operation Spalax was a campaign that primarily targeted Colombian government organizations and private companies, particularly those associated with the energy and metallurgical industries. The Operation Spalax threat actors distributed commodity malware and tools using generic phishing topics related to COVID-19, banking, and law enforcement action. Security researchers noted indicators of compromise and some infrastructure overlaps with other campaigns dating back to April 2018, including at least one separately attributed to APT-C-36, however identified enough differences to report this as separate, unattributed activity.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.7
Created
Modified
Raw hash
1e7d2304daba7706...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.7Current bundle1e7d2304daba…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  2. [2]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  3. [3]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  4. [4]
    Recorded Future TAG-144 AUG 2025

    Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.

    Open source URL
  5. [5]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  6. [6]
    Citizen Lab Group5

    Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

    Open source URL
  7. [7]
    Proofpoint Operation Transparent Tribe March 2016

    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

    Open source URL
  8. [8]
    ESET Operation Spalax Jan 2021

    M. Porolli. (2021, January 21). Operation Spalax: Targeted malware attacks in Colombia. Retrieved September 16, 2022.

    Open source URL
  9. [9]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  10. [10]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  11. [11]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  12. [12]
    Unit 42 Gorgon Group Aug 2018

    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

    Open source URL
  13. [13]
    Proofpoint TA2541 February 2022

    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

    Open source URL
  14. [14]
    Cisco Operation Layover September 2021

    Ventura, V. (2021, September 16). Operation Layover: How we tracked an attack on the aviation industry to five years of compromise. Retrieved September 15, 2023.

    Open source URL
  15. [15]
    Bladabindi

    (Citation: Fidelis njRAT June 2013)(Citation: Trend Micro njRAT 2018)

  16. [16]
    Bladabindi

    (Citation: Fidelis njRAT June 2013)(Citation: Trend Micro njRAT 2018)

  17. [17]
    Bladabindi

    (Citation: Fidelis njRAT June 2013)(Citation: Trend Micro njRAT 2018)

  18. [18]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  19. [19]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  20. [20]
    FireEye Njw0rm Aug 2013

    Dawda, U. and Villeneuve, N. (2013, August 30). Njw0rm - Brother From the Same Mother. Retrieved November 17, 2024.

    Open source URL
  21. [21]
    FireEye Njw0rm Aug 2013

    Dawda, U. and Villeneuve, N. (2013, August 30). Njw0rm - Brother From the Same Mother. Retrieved November 17, 2024.

    Open source URL
  22. [22]
    FireEye Njw0rm Aug 2013

    Dawda, U. and Villeneuve, N. (2013, August 30). Njw0rm - Brother From the Same Mother. Retrieved November 17, 2024.

    Open source URL
  23. [23]
    LV

    (Citation: Fidelis njRAT June 2013)

  24. [24]
    LV

    (Citation: Fidelis njRAT June 2013)

  25. [25]
    LV

    (Citation: Fidelis njRAT June 2013)

  26. [26]
    Njw0rm

    Some sources have discussed Njw0rm as a later variant of [njRAT](https://attack.mitre.org/software/S0385), where Njw0rm adds the ability to spread via removable devices such as USB drives.(Citation: FireEye Njw0rm Aug 2013) Other sources contain that functionality in their description of [njRAT](https://attack.mitre.org/software/S0385) itself.(Citation: Fidelis njRAT June 2013)(Citation: Trend Micro njRAT 2018)

  27. [27]
    Njw0rm

    Some sources have discussed Njw0rm as a later variant of [njRAT](https://attack.mitre.org/software/S0385), where Njw0rm adds the ability to spread via removable devices such as USB drives.(Citation: FireEye Njw0rm Aug 2013) Other sources contain that functionality in their description of [njRAT](https://attack.mitre.org/software/S0385) itself.(Citation: Fidelis njRAT June 2013)(Citation: Trend Micro njRAT 2018)

  28. [28]
    Njw0rm

    Some sources have discussed Njw0rm as a later variant of [njRAT](https://attack.mitre.org/software/S0385), where Njw0rm adds the ability to spread via removable devices such as USB drives.(Citation: FireEye Njw0rm Aug 2013) Other sources contain that functionality in their description of [njRAT](https://attack.mitre.org/software/S0385) itself.(Citation: Fidelis njRAT June 2013)(Citation: Trend Micro njRAT 2018)

  29. [29]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  30. [30]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  31. [31]
    mitre-attackS0385
    Open source URL
  32. [32]
    mitre-attackS0385
    Open source URL
  33. [33]
    mitre-attackS0385
    Open source URL
  34. [34]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  35. [35]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  36. [36]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  37. [37]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  38. [38]
    Recorded Future TAG-144 AUG 2025

    Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.

    Open source URL
  39. [39]
    Citizen Lab Group5

    Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

    Open source URL
  40. [40]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  41. [41]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  42. [42]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  43. [43]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  44. [44]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  45. [45]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  46. [46]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  47. [47]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  48. [48]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  49. [49]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  50. [50]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  51. [51]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  52. [52]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  53. [53]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  54. [54]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  55. [55]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  56. [56]
    Proofpoint Operation Transparent Tribe March 2016

    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

    Open source URL
  57. [57]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  58. [58]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  59. [59]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  60. [60]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  61. [61]
    Citizen Lab Group5

    Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

    Open source URL
  62. [62]
    Citizen Lab Group5

    Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

    Open source URL
  63. [63]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  64. [64]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  65. [65]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  66. [66]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  67. [67]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  68. [68]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  69. [69]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  70. [70]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  71. [71]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  72. [72]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  73. [73]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  74. [74]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  75. [75]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  76. [76]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  77. [77]
    Citizen Lab Group5

    Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

    Open source URL
  78. [78]
    Citizen Lab Group5

    Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

    Open source URL
  79. [79]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  80. [80]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  81. [81]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  82. [82]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  83. [83]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  84. [84]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  85. [85]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  86. [86]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  87. [87]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  88. [88]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  89. [89]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  90. [90]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  91. [91]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  92. [92]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  93. [93]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  94. [94]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  95. [95]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  96. [96]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  97. [97]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  98. [98]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  99. [99]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  100. [100]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  101. [101]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  102. [102]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  103. [103]
    ESET Operation Spalax Jan 2021

    M. Porolli. (2021, January 21). Operation Spalax: Targeted malware attacks in Colombia. Retrieved September 16, 2022.

    Open source URL
  104. [104]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  105. [105]
    Citizen Lab Group5

    Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

    Open source URL
  106. [106]
    Citizen Lab Group5

    Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

    Open source URL
  107. [107]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  108. [108]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  109. [109]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  110. [110]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  111. [111]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  112. [112]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  113. [113]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  114. [114]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  115. [115]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  116. [116]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  117. [117]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  118. [118]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  119. [119]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  120. [120]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  121. [121]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  122. [122]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  123. [123]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  124. [124]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  125. [125]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  126. [126]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  127. [127]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  128. [128]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  129. [129]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  130. [130]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  131. [131]
    Unit 42 Gorgon Group Aug 2018

    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

    Open source URL
  132. [132]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  133. [133]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  134. [134]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  135. [135]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  136. [136]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.