Skip to content

Malware

RoarBAT

According to SOCRadar, this is a batch script that uses WinRAR to delete files with target file extensions from a disk.

RoarBAT is a Windows malware family operated by Sandworm.

Background

SOCRadar describes this as a batch script that leverages WinRAR to wipe files matching specific extensions off a disk.


Source: Malpedia (Fraunhofer FKIE).