typeentityconfidencemediumupdated2026-08-08dotnetratinfostealerc2persistencedefense-evasionimpactmalware-family

ratonrat

Spanish/Latin American branded .NET Framework 4.x commodity RAT family sold as a builder kit (clientForCrypters.exe). Full-spectrum surveillance: HVNC hidden desktop, browser credential cloning via DPAPI + SQLite, keylogging, screen/webcam/mic capture, WiFi theft, RunPE process injection, and modular ransomware/locker/screamer impact forms. Packaged with Costura.Fody IL merging. No packing, no obfuscation — all class/namespace names readable.

Build Stack

  • Language: C# / .NET Framework 4.x
  • Linker: Costura.Fody 6.x for IL merging of dependencies into single deployable EXE
  • Dependencies: AForge.Video.DirectShow (webcam), NAudio 2.3.0 (microphone/audio), Newtonsoft.Json 13.0.0 (C2 serialization), custom Stuff.dll helper
  • Packing: None — plain .NET with embedded compressed resources
  • Obfuscation: None observed — full symbol readability
  • Signing: Unsigned
  • Timestamps: Fabricated future dates (2046–2101 range observed) ^[sample e8573e97/exiftool.json]

Deploy / TTPs

Capability Evidence
Hidden VNC (HVNC) HvncCommand, hvncThread, doHvnc, isDesktopCapturing ^[sample 667f1f97/strings.txt:5193-5984]
Browser credential cloning CloneChrome, CloneFirefox, CloneEdge, CloneOpera, CloneBrave, CloneOperaGX ^[sample 667f1f97/strings.txt:4278-4624]
DPAPI secret decryption Raton.Helper.DPAPI, DecryptPassword, Shit.DPapi ^[sample 667f1f97/strings.txt:4712-6093]
SQLite browser database access SqliteMasterEntry, SqlStatement, ReadCookies, EatCookies ^[sample 667f1f97/strings.txt:7771-6959]
WiFi credential theft WifiGrab ^[sample 667f1f97/strings.txt:4882]
Keystroke capture HandleKeylogger, KeyCaptureLoop ^[sample 667f1f97/strings.txt:6698-7862]
Screen capture SendScreenshot, capture screenshot (5 matches) ^[sample 667f1f97/capa.txt:151]
Clipboard hijack CheckClipboard, LastClipboardText ^[sample 667f1f97/strings.txt:4196-7578]
Webcam/mic capture HasCamera, HasMicrophone, SendCameraList, SendAudioSafe ^[sample 667f1f97/strings.txt:4855-5645]
RunPE process injection HandleRunPE, DelegateVirtualAllocEx, DelegateWriteProcessMemory ^[sample 667f1f97/strings.txt:4690-7756]
UAC bypass Commands.Handlers.UAC ^[sample 667f1f97/strings.txt:4645]
Registry Run persistence persist via Run registry key (6 matches) ^[sample 667f1f97/capa.txt:275]
Scheduled task persistence schedule task via schtasks (8 matches) ^[sample 667f1f97/capa.txt:277]
Anti-VM QEMU, VMware, VirtualBox, Xen string references ^[sample 667f1f97/capa.txt:133-141]
Anti-debug CheckRemoteDebuggerPresent, WudfIsAnyDebuggerPresent ^[sample 667f1f97/capa.txt:131-133]
Self-deletion self delete (6 matches) ^[sample 667f1f97/capa.txt:132]
Defender tampering disable Windows Defender features via registry on Windows ^[sample 667f1f97/capa.txt:264]
Ransomware/locker modules Ransomware, LockScreen, InputBlock, Screamer, Jigsaw, WPro ^[sample 667f1f97/strings.txt:6936-6946]
C2 protocol Async TCP client/server with HTTP fallback, Newtonsoft.Json serialization ^[sample 667f1f97/capa.txt:158-161]

Variants / Aliases

  • OpenCTI labels: ratonrat (primary), clipbanker (feature-limited variant emphasizing clipboard hijacking), njrat (false positive on sample 3f434324 — no NJRat code artefacts observed)
  • Internal name: clientForCrypters.exe across all confirmed siblings
  • Namespace: Client.Shit.Packaged / Client.Raton / Raton.Classes

Notable Analyses

  • 667f1f97d015 — 2.5 MB, .NET Framework 4.x, full capability set, no obfuscation ^[/intel/analyses/667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9.html]
  • e8573e97c75b — 3.7 MB sibling, identical internal name, ratonrat OpenCTI label ^[sample e8573e97/triage.json]
  • 58a919673d1c — 2.5 MB sibling, ratonrat label ^[sample 58a91967/triage.json]
  • 9f21280ec273 — 2.5 MB sibling, ratonrat label
  • da590d16a873 — 2.6 MB sibling, ratonrat label
  • 13dd71dc7122 — 3.1 MB sibling, clipbanker label
  • 88a2c9db752d — 3.0 MB sibling, clipbanker label
  • e8c84a211316 — 2.9 MB sibling, clipbanker label
  • 3f434324ac70 — 3.7 MB sibling, njrat label (false positive)
  • fddc9cca767e — 2.5 MB sibling, no family label

Capabilities

  • hvnc-hidden-desktop-control
  • browser-credential-dpapi-clone
  • sqlite-cookie-password-theft
  • wifi-credential-harvest
  • keystroke-logging-hook-and-poll
  • clipboard-monitor-hijack
  • webcam-directshow-capture
  • microphone-naudio-capture
  • screenshot-winapi-capture
  • runpe-process-hollowing
  • uac-bypass-handler
  • registry-run-persistence
  • schtasks-scheduled-persistence
  • defender-registry-disable
  • anti-vm-qemu-vmware-vbox-xen
  • anti-debug-checkremotedebuggerpresent
  • self-deletion-comspec
  • tcp-client-server-c2
  • http-fallback-c2
  • newtonsoft-json-serialization
  • costura-fody-il-merging
  • modular-ransomware-locker-screamer
  • async-await-c2-supervisor

Related