Skip to content

RAT

WmRAT

According to Proofpoint, WmRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT functionality.

WmRAT is a Windows rat operated by HAZY TIGER.

Background

Proofpoint describes WmRAT as a C++ remote access trojan that relies on sockets for its communications and offers the usual RAT feature set. It can collect basic host details, transfer files in either direction, capture screenshots, obtain the target machine's geolocation, list directories and files, and execute arbitrary commands through cmd or PowerShell. The malware additionally spins up a number of meaningless junk threads, possibly to throw off researchers or responders examining the samples.


Source: Malpedia (Fraunhofer FKIE).