LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0385: njRAT

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.[1]

EnterpriseS0385MalwareObject v1.7Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S0385: njRAT describes [njRAT](https://attack.mitre.org/software/S0385) is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.(Citation: Fidelis njRAT June 2013)

Executive priority

S0385: njRAT is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S0385: njRAT by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata
  • Network, endpoint, and security-tool telemetry

Detection direction

  • Validate whether S0385: njRAT appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

njRAT

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

31 rows
DomainIDNameRelationship / procedure
EnterpriseT1082System Information Discovery

njRAT enumerates the victim operating system and computer name during the initial infection.[1]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

njRAT has a module that steals passwords saved in victim web browsers.[1][2]CitationCitizen Lab Group5

EnterpriseT1010Application Window Discovery

njRAT gathers information about opened windows during the initial infection.[1]

EnterpriseT1105Ingress Tool Transfer

njRAT can download files to the victim’s machine.[1][2] APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies.CitationKaspersky BlindEagle AUG 2024

EnterpriseT1083File and Directory Discovery

njRAT can browse file systems using a file manager module.[1]

EnterpriseT1012Query Registry

njRAT can read specific registry values.[2]

EnterpriseT1120Peripheral Device Discovery

njRAT will attempt to detect if the victim system has a camera during the initial infection. njRAT can also detect any removable drives connected to the system.[1][2]

EnterpriseT1125Video Capture

njRAT can access the victim's webcam.[1]CitationCitizen Lab Group5

EnterpriseT1113Screen Capture

njRAT can capture screenshots of the victim’s machines.[2]CitationKaspersky BlindEagle AUG 2024

EnterpriseT1106Native API

njRAT has used the ShellExecute() function within a script.[2]

EnterpriseT1018Remote System Discovery

njRAT can identify remote hosts on connected networks.[1]

EnterpriseT1070.004File DeletionSub-technique

njRAT is capable of deleting files.[1][2]

EnterpriseT1059.001PowerShellSub-technique

njRAT has executed PowerShell commands via auto-run registry key persistence.[2]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

njRAT has included a base64 encoded executable.[2]

EnterpriseT1132.001Standard EncodingSub-technique

njRAT uses Base64 encoding for C2 traffic.[1]

EnterpriseT1027.004Compile After DeliverySub-technique

njRAT has used AutoIt to compile the payload and main script into a single executable after delivery.[2]

EnterpriseT1571Non-Standard Port

njRAT has used port 1177 for HTTP C2 communications.[2]

EnterpriseT1091Replication Through Removable Media

njRAT can be configured to spread via removable drives.[1][2]

EnterpriseT1033System Owner/User Discovery

njRAT enumerates the current user during the initial infection.[1]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

njRAT has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\ and dropped a shortcut in %STARTUP%.[1][2]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

njRAT has a module for performing remote desktop access.[1]CitationKaspersky BlindEagle AUG 2024

EnterpriseT1056.001KeyloggingSub-technique

njRAT is capable of logging keystrokes.[1][2]CitationCitizen Lab Group5CitationKaspersky BlindEagle AUG 2024

EnterpriseT1071.001Web ProtocolsSub-technique

njRAT has used HTTP for C2 communications.[2]

EnterpriseT1686.003Windows Host FirewallSub-technique

njRAT has modified the Windows firewall to allow itself to communicate through the firewall.[1][2]

EnterpriseT1070.009Clear PersistenceSub-technique

njRAT is capable of manipulating and deleting registry keys, including those used for persistence.[2]

EnterpriseT1112Modify Registry

njRAT can create, delete, or modify a specified Registry key or value.[1][2]

EnterpriseT1041Exfiltration Over C2 Channel

njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information.[2]CitationKaspersky BlindEagle AUG 2024

EnterpriseT1057Process Discovery

njRAT can search a list of running processes for Tr.exe.[2]

EnterpriseT1568.001Fast Flux DNSSub-technique

njRAT has used a fast flux DNS for C2 IP resolution.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

njRAT can launch a command shell interface for executing commands.[1]

EnterpriseT1005Data from Local System

njRAT can collect data from a local system.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0078: Gorgon Group

Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States. [1]

GroupEnterprise

G1018: TA2541

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.[1][2]

GroupEnterprise

G0143: Aquatic Panda

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.[1]

GroupEnterprise

G0043: Group5

Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes. Group5 has used two commonly available remote access tools (RATs), njRAT and NanoCore, as well as an Android RAT, DroidJack. [1]

GroupEnterprise

G0099: APT-C-36

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.[1][2][3][4]

CampaignEnterprise

C0005: Operation Spalax

Operation Spalax was a campaign that primarily targeted Colombian government organizations and private companies, particularly those associated with the energy and metallurgical industries. The Operation Spalax threat actors distributed commodity malware and tools using generic phishing topics related to COVID-19, banking, and law enforcement action. Security researchers noted indicators of compromise and some infrastructure overlaps with other campaigns dating back to April 2018, including at least one separately attributed to APT-C-36, however identified enough differences to report this as separate, unattributed activity.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.7
Created
Modified
Raw hash
1e7d2304daba7706...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.7Current bundle1e7d2304daba…
19.11.7Older bundle1e7d2304daba…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  2. [2]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  3. [3]
    Bladabindi

    (Citation: Fidelis njRAT June 2013)(Citation: Trend Micro njRAT 2018)

  4. [4]
    FireEye Njw0rm Aug 2013

    Dawda, U. and Villeneuve, N. (2013, August 30). Njw0rm - Brother From the Same Mother. Retrieved November 17, 2024.

    Open source URL
  5. [5]
    LV

    (Citation: Fidelis njRAT June 2013)

  6. [6]
    Njw0rm

    Some sources have discussed Njw0rm as a later variant of [njRAT](https://attack.mitre.org/software/S0385), where Njw0rm adds the ability to spread via removable devices such as USB drives.(Citation: FireEye Njw0rm Aug 2013) Other sources contain that functionality in their description of [njRAT](https://attack.mitre.org/software/S0385) itself.(Citation: Fidelis njRAT June 2013)(Citation: Trend Micro njRAT 2018)

  7. [7]
    mitre-attackS0385
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.