typeanalysisfamilyratonratconfidencemediumdotnetratinfostealerc2persistencedefense-evasionimpactmitre-attck
SHA-256: 667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9

ratonrat: 667f1f97d015 — .NET Framework 4.x full-spectrum RAT, HVNC + browser theft + ransomware module

Executive Summary

A 2.5 MB .NET Framework 4.x GUI PE32 labeled clientForCrypters.exe — a full-spectrum commodity RAT with Hidden VNC (HVNC), browser credential cloning via DPAPI + SQLite, keylogging, screen/webcam/mic capture, WiFi credential theft, process injection (RunPE), and modular ransomware/locker/screamer impact forms. Packaged with Costura.Fody IL merging. Ten confirmed siblings share identical internal naming. Static-only analysis (CAPE skipped — no Windows guest). ^[file.txt] ^[exiftool.json]

What It Is

Attribute Value
SHA-256 667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9
File type PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections ^[file.txt]
Size 2,508,288 bytes
Timestamp Fri Nov 6 11:12:38 2048 UTC (fabricated future date) ^[pefile.txt:34] ^[exiftool.json:15]
Internal name clientForCrypters.exe ^[exiftool.json:41]
Original filename clientForCrypters.exe ^[exiftool.json:43]
VS_VERSIONINFO FileDescription="Application", ProductName="Application", Copyright="Copyright © 2026" ^[exiftool.json:38-44]
Linker Version 48.0 (non-standard; .NET IL assembler) ^[pefile.txt:45]
Build toolchain .NET Framework 4.x, Costura.Fody 6.0.0.0 for IL merging ^[strings.txt:4119]
Signed No ^[rabin2-info.txt:27]
Packing None — plain .NET with embedded compressed dependencies ^[capa.txt:178]
Obfuscation None observed — class/namespace names fully readable ^[strings.txt:7865-7871]
Family ratonrat (medium confidence; 10 confirmed siblings share clientForCrypters.exe internal name)

The clientForCrypters.exe name implies a builder-kit distribution model: a "crypter client" sold to other criminals who configure and deploy it. The Client.Shit.Packaged namespace and Raton branding (Spanish for "rat") suggest a Spanish-speaking or Latin American developer community. ^[strings.txt:4995] ^[strings.txt:6999]

How It Works

Core architecture. The binary is a self-contained .NET Framework GUI application whose dependencies are IL-merged into the main assembly via Costura.Fody. At runtime, embedded compressed DLLs are decompressed from .rsrc and loaded into the AppDomain. ^[capa.txt:178] Notable embedded libraries: AForge.Video.DirectShow (webcam), NAudio 2.3.0.0 (microphone/audio), Newtonsoft.Json 13.0.0.0 (C2 serialization), and a custom Stuff.dll helper (12,288 bytes). ^[strings.txt:4116-4129]

C2 and communication. The RAT acts as both TCP client and TCP server, with HTTP fallback for C2. Capa reports act as TCP client (4 matches), start TCP server (2 matches), create HTTP request, receive HTTP response, and send HTTP request with Host header. ^[capa.txt:160-158] No hardcoded C2 endpoints were recovered statically — configuration is likely runtime-loaded or embedded in an encrypted resource not visible in plaintext strings. The Client.Raton.Supervisor+<Run>d__14 and Client.Raton.Supervisor+<OpenConnection>d__16 async state-machine strings confirm an async/await C2 connection loop. ^[strings.txt:7865-7866]

Surveillance suite. Comprehensive victim monitoring: capture screenshot (5 matches) ^[capa.txt:151], log keystrokes via application hook and log keystrokes via polling (3 matches) ^[capa.txt:146-149], read clipboard data (2 matches) and write clipboard data (3 matches) ^[capa.txt:180-181], webcam capture via AForge.DirectShow (HasCamera, GetCamerasList, SendCameraList), ^[strings.txt:4855-7542] and microphone capture via NAudio (HasMicrophone, SendAudioSafe). ^[strings.txt:5645-5340] HVNC hidden desktop is explicitly present: HvncCommand, hvncThread, hvncThreadRunning, isDesktopCapturing, doHvnc. ^[strings.txt:5193-5984]

Credential and data theft. Browser credential cloning across all major browsers: CloneChrome, CloneFirefox, CloneEdge, CloneOpera, CloneOperaGX, CloneBrave — each with dedicated async handler state machines. ^[strings.txt:4278-4624] DPAPI is used for secret decryption (Raton.Helper.DPAPI, DecryptPassword, Shit.DPapi). ^[strings.txt:4712-6093] SQLite access for browser database reading (SqliteMasterEntry, SqlStatement, ReadCookies, EatCookies). ^[strings.txt:7771-6959] WiFi credential theft via WifiGrab. ^[strings.txt:4882]

Process injection and escalation. RunPE-style process hollowing is supported: HandleRunPE, DelegateVirtualAllocEx, DelegateWriteProcessMemory, SuspendThread, ResumeThread. ^[strings.txt:4690-7756] UAC bypass is handled by Commands.Handlers.UAC. ^[strings.txt:4645] Acquire debug privileges and enter debug mode in .NET are flagged by capa. ^[capa.txt:238-239]

Impact modules. Embedded .resources files reveal modular impact forms: Ransomware, LockScreen, InputBlock, Screamer, Jigsaw, WPro. ^[strings.txt:6936-6946] These are accompanied by EncryptFile, DecryptFile, Change the wallpaper, Hide the Windows taskbar, and Swap mouse buttons capabilities. ^[capa.txt:212-217] A Chat form and game forms (Snake, MineSweeper) are also present, suggesting taunting or distraction features. ^[strings.txt:6945-6942]

Persistence and evasion. Registry Run keys (persist via Run registry key (6 matches)) ^[capa.txt:275] and scheduled tasks (schedule task via schtasks (8 matches)) ^[capa.txt:277]. Anti-VM references targeting QEMU, VMware, VirtualBox, and Xen. ^[capa.txt:133-141] Anti-debug via CheckRemoteDebuggerPresent and WudfIsAnyDebuggerPresent. ^[capa.txt:131-133] Self-deletion (6 matches). ^[capa.txt:132] Windows Defender tampering via registry (disable Windows Defender features via registry on Windows). ^[capa.txt:264]

Decompiled Behavior

Radare2 analysis recovered 3,324 CIL methods. The entry point lands at method.Program.Main (0x4043d8), which bootstraps the WinForms GUI and initializes the Client.Raton.Supervisor async C2 loop. ^[rabin2-info.txt:2] Key async state machines observed:

  • Client.Raton.Supervisor+<Run>d__14 — main C2 supervisor loop ^[strings.txt:7865]
  • Client.Raton.Supervisor+<OpenConnection>d__16 — TCP connection handshake ^[strings.txt:7866]
  • Client.Raton.PacketSender+<Send>d__4 — outbound packet dispatch ^[strings.txt:7867]
  • Client.Raton.PacketReader+<Run>d__6 — inbound packet processing ^[strings.txt:7868]
  • Commands.HVNCHandler+<HandleCloneChrome>d__28 through +<HandleCloneEdge>d__33 — per-browser credential cloning ^[strings.txt:7855-7860]
  • Commands.Handlers.HandleKeylogger+<KeyCaptureLoop>d__22 — keystroke capture ^[strings.txt:7862]

The .NET type system is unobfuscated; all namespaces, classes, and method names are human-readable, confirming either an unprotected builder output or a developer unconcerned with static analysis.

C2 Infrastructure

No hardcoded IP addresses, domains, or URLs were recovered from static strings. The C2 endpoint is runtime-resolved, likely from:

  1. An encrypted configuration block loaded at startup
  2. A companion file or registry-staged config
  3. A hardcoded decryption routine with embedded ciphertext (not visible in plaintext strings)

The Client.Raton.Supervisor+<OpenConnection>d__16 async method and host/port compiler-generated fields (<host>5__2, <port>5__3) confirm the endpoint is assembled at runtime. ^[strings.txt:4451-4500]

Interesting Tidbits

  • Builder-kit branding. The clientForCrypters.exe name and Client.Shit.Packaged namespace strongly suggest this is a commercial builder output sold to less-technical criminals — the kind who need a "client for crypters" to pair with their stub. ^[strings.txt:5879] ^[strings.txt:4995]
  • Future timestamp. The PE timestamp of November 2048 is impossible and serves as a crude anti-forensic measure, or simply a default from a misconfigured build environment. ^[pefile.txt:34]
  • Fody marker. clientForCrypters_ProcessedByFody confirms Costura.Fody 6.x was used to IL-merge all dependencies into a single deployable EXE. ^[strings.txt:7697]
  • Embedded games. The .resources section contains game forms (Snake, MineSweeper, Chat) alongside ransomware and lock-screen forms, suggesting the builder includes "prank" or taunt modules. ^[strings.txt:6936-6946]
  • HVNC naming. The HvncCommand / doHvnc strings use the industry-standard abbreviation for Hidden VNC — a technique for covert interactive desktop control without visible windows. ^[strings.txt:4898-4953]
  • No packing, no obfuscation. Despite the sophisticated feature set, the binary is completely unobfuscated. Every class, method, and namespace is readable. This is consistent with a builder kit where the buyer receives pre-compiled output rather than source code.
  • Siblings span multiple OpenCTI labels. Ten confirmed siblings share the clientForCrypters.exe internal name, yet OpenCTI labels them ratonrat, clipbanker, and njrat. The njrat label on sample 3f434324 is likely a false positive; clipbanker may reflect a feature-limited variant with clipboard hijacking emphasized.

How To Mess With It (Homelab Replication)

Toolchain: .NET Framework 4.7.2+ targeting x86, Visual Studio 2022 or VS BuildTools, Costura.Fody 6.x NuGet package.

Build recipe:

  1. Create a new .NET Framework WinForms project in C#.
  2. Install Costura.Fody and Fody NuGet packages.
  3. Add dependencies: AForge.Video.DirectShow, NAudio, Newtonsoft.Json, System.Drawing.
  4. Write async TCP client/server classes with TcpClient/TcpListener.
  5. Add browser credential cloning using System.Data.SQLite + System.Security.Cryptography.ProtectedData (DPAPI).
  6. Build in Release mode. Fody will embed and compress all dependencies into .rsrc.

Verification: Run capa <reproducer.exe> and compare to this sample's capa.txt. You should see matching hits for act as TCP client, capture screenshot, log keystrokes, read clipboard data, create process in .NET, and embed dependencies as resources using Fody/Costura.

What you'll learn: How a commodity .NET RAT builder assembles a full-spectrum surveillance binary from open-source libraries, and how Costura.Fody changes the static-analysis surface by hiding DLL boundaries.

Deployable Signatures

YARA Rule

rule RatonRAT_Generic {
    meta:
        description = "RatonRAT .NET Framework RAT family — clientForCrypters variant"
        author = "PacketPursuit SOC"
        reference = "/intel/analyses/667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9.html"
        date = "2026-08-08"
        hash = "667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9"
    strings:
        $a1 = "clientForCrypters.exe" ascii wide
        $a2 = "Client.Raton.Supervisor" ascii wide
        $a3 = "Raton.Helper.DPAPI" ascii wide
        $a4 = "Client.Shit.Packaged" ascii wide
        $a5 = "HvncCommand" ascii wide
        $a6 = "doHvnc" ascii wide
        $a7 = "HandleCloneChrome" ascii wide
        $a8 = "WifiGrab" ascii wide
        $b1 = "costura.aforge.video.directshow.dll.compressed" ascii wide
        $b2 = "costura.naudio.core.dll.compressed" ascii wide
        $b3 = "costura.newtonsoft.json.dll.compressed" ascii wide
        $b4 = "costura.stuff.dll.compressed" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        (2 of ($a*) or 2 of ($b*))
}

Behavioral Hunt Query (Sigma-like)

title: RatonRAT Process and Network Behavior
detection:
    selection_process:
        - Image|endswith: 'clientForCrypters.exe'
        - CommandLine|contains: 'clientForCrypters'
    selection_network:
        - Initiated: true
        - DestinationPort:
            - 4444
            - 5555
            - 6666
            - 7777
            - 8888
            - 9999
    selection_registry:
        - EventType: SetValue
        - TargetObject|contains:
            - '\\Software\\Microsoft\\Windows\\CurrentVersion\\Run'
            - '\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce'
    selection_file:
        - TargetFilename|contains:
            - '\\AppData\\Roaming\\'
            - '\\AppData\\Local\\'
            - '\\Temp\\'
        - Image|endswith: 'clientForCrypters.exe'
    condition: selection_process or (selection_network and selection_file) or selection_registry

IOC List

Indicator Value Type
SHA-256 667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9 Hash
SHA-256 e8573e97c75bec4b9645f40c94a1f961971aa28444e3726564f4dda1312aac25 Sibling hash
SHA-256 58a919673d1c3d581fe9e14a437a94297a77cce098191c286d5021a2211d6130 Sibling hash
SHA-256 9f21280ec273b0581cf6b2ff6ca6852d479c161b0d208691c8e6e401ee11b216 Sibling hash
SHA-256 da590d16a8738a6c5f055fffcdcb49870e088d37e040bf1fc1880cbf9b3faa51 Sibling hash
Internal filename clientForCrypters.exe Static string
VS_VERSIONINFO FileDescription="Application", InternalName="clientForCrypters.exe", Copyright="Copyright © 2026" Version info
Costura marker clientForCrypters_ProcessedByFody Build artefact
Embedded DLL costura.stuff.dll.compressed Resource name
HVNC strings HvncCommand, hvncThread, doHvnc Capability strings
Browser clone strings CloneChrome, CloneFirefox, CloneEdge, CloneOpera, CloneBrave, CloneOperaGX Capability strings
Registry persistence HKCU\Software\Microsoft\Windows\CurrentVersion\Run Persistence path
Schtasks persistence schtasks /create Persistence mechanism

Behavioral Fingerprint

This binary is a .NET Framework WinForms GUI executable with a large .rsrc section containing compressed embedded DLLs (Costura.Fody pattern). Upon execution, it initializes an async TCP client/server C2 loop (Client.Raton.Supervisor), enumerates browser credential stores via DPAPI + SQLite (CloneChrome, CloneFirefox, etc.), captures the screen via System.Drawing, logs keystrokes via application hooks or polling, hijacks the clipboard, and optionally launches a Hidden VNC desktop (HvncCommand). It persists via registry Run keys and scheduled tasks. The process makes outbound TCP connections within 30 seconds of launch and may spawn child processes via CreateProcessW with modified I/O handles for RunPE injection.

Detection Signatures

MITRE ATT&CK ID Technique Evidence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys capa persist via Run registry key (6 matches) ^[capa.txt:275]
T1053.005 Scheduled Task/Job: Scheduled Task capa schedule task via schtasks (8 matches) ^[capa.txt:277]
T1056.001 Input Capture: Keylogging capa log keystrokes via application hook, log keystrokes via polling (3 matches) ^[capa.txt:146-149]
T1113 Screen Capture capa capture screenshot (5 matches) ^[capa.txt:151]
T1115 Clipboard Data capa read clipboard data (2 matches), write clipboard data (3 matches) ^[capa.txt:180-181]
T1059 Command and Scripting Interpreter capa compile CSharp in .NET, compile Visual Basic in .NET ^[capa.txt:273-274]
T1620 Reflective Code Loading capa invoke .NET assembly method (2 matches), load .NET assembly (3 matches) ^[capa.txt:270-272]
T1497.001 Virtualization/Sandbox Evasion: System Checks capa reference anti-VM strings targeting QEMU/VMware/VirtualBox/Xen ^[capa.txt:133-141]
T1562.001 Impair Defenses: Disable or Modify Tools capa disable Windows Defender features via registry on Windows ^[capa.txt:264]
T1070.004 Indicator Removal: File Deletion capa self delete (6 matches) ^[capa.txt:132]
T1027 Obfuscated Files or Information capa Obfuscated Files or Information, Compile After Delivery ^[capa.txt:26-28]
T1213 Data from Information Repositories capa Data from Information Repositories ^[capa.txt:16]
T1087 Account Discovery capa Account Discovery ^[capa.txt:34]
T1083 File and Directory Discovery capa File and Directory Discovery ^[capa.txt:36]
T1012 Query Registry capa Query Registry ^[capa.txt:38]
T1518 Software Discovery capa Software Discovery ^[capa.txt:39]
T1082 System Information Discovery capa System Information Discovery ^[capa.txt:40]
T1016 System Network Configuration Discovery capa System Network Configuration Discovery ^[capa.txt:42]
T1033 System Owner/User Discovery capa System Owner/User Discovery ^[capa.txt:43]
T1129 Shared Modules capa Shared Modules ^[capa.txt:44]
T1047 Windows Management Instrumentation capa Windows Management Instrumentation ^[capa.txt:45]
T1496 Resource Hijacking capa Resource Hijacking ^[capa.txt:46]
T1134 Access Token Manipulation capa Access Token Manipulation ^[capa.txt:50]
T1095 Non-Application Layer Protocol capa act as TCP client (4 matches), start TCP server (2 matches) ^[capa.txt:160-161]

References

Provenance

  • file.txt — file(1) output, version unknown
  • exiftool.json — ExifTool 12.76
  • pefile.txt — pefile Python library
  • strings.txt — GNU strings (7,893 lines)
  • capa.txt — Mandiant capa v7.0.1 static analysis
  • rabin2-info.txt — radare2 5.x rabin2 -I
  • binwalk.txt — Binwalk v2.3.3
  • floss.txt — FireEye flare-floss (errored; no decoded output)
  • dynamic-analysis.md — CAPE sandbox skipped (no Windows guest available)
  • Radare2 analysis: 3,324 functions recovered from CIL, entry at method.Program.Main