Skip to content

RAT

STRRAT

STRRAT is a Java-based RAT, which makes extensive use of plugins to provide full remote access to an attacker, as well as credential stealing, key logging and additional plugins.

STRRAT is a Java rat.

Background

STRRAT is a Java-based RAT that relies heavily on plugins to give an attacker complete remote access, alongside credential theft, keylogging, and other plugin-driven features. Its main emphasis is on stealing credentials from browsers and email clients and capturing passwords through keylogging, with support for Firefox, Internet Explorer, Chrome, Foxmail, Outlook, and Thunderbird.

From Version 1.2 onward, STRRAT became notorious for ransomware-style behavior, tacking the .crimson extension onto files. Version 1.5 is considerably more obfuscated and modular than earlier builds, yet its backdoor capabilities are largely unchanged: harvesting browser passwords, running remote and PowerShell commands, logging keystrokes, and more. Version 1.5 adds a genuine encryption routine, although it is still fairly easy to reverse at present.


Source: Malpedia (Fraunhofer FKIE).