Skip to content

RAT

StormKittyRAT

According to unpac.me, StormKitty is a Remote Access Trojan (RAT), written in C#, primarily designed to perform extensive system reconnaissance and data collection.

StormKittyRAT is a Windows rat.

Background

Per unpac.me, StormKitty is a C#-written Remote Access Trojan (RAT) built chiefly for broad system reconnaissance and data gathering. It uses Windows Management Instrumentation to execute and carries out detailed system profiling, querying the registry, identifying owners and users, and mapping network configurations. The RAT can also pull data from information repositories and enumerate files and directories. To evade defenses, it obfuscates files or information and checks for virtualization or sandbox environments before proceeding. Together these features let StormKitty persist on a host and extract sensitive data from compromised machines.


Source: Malpedia (Fraunhofer FKIE).