ratonrat
Spanish/Latin American branded .NET Framework 4.x commodity RAT family sold as a builder kit (clientForCrypters.exe). Full-spectrum surveillance: HVNC hidden desktop, browser credential cloning via DPAPI + SQLite, keylogging, screen/webcam/mic capture, WiFi theft, RunPE process injection, and modular ransomware/locker/screamer impact forms. Packaged with Costura.Fody IL merging. No packing, no obfuscation — all class/namespace names readable.
Build Stack
- Language: C# / .NET Framework 4.x
- Linker: Costura.Fody 6.x for IL merging of dependencies into single deployable EXE
- Dependencies: AForge.Video.DirectShow (webcam), NAudio 2.3.0 (microphone/audio), Newtonsoft.Json 13.0.0 (C2 serialization), custom
Stuff.dllhelper - Packing: None — plain .NET with embedded compressed resources
- Obfuscation: None observed — full symbol readability
- Signing: Unsigned
- Timestamps: Fabricated future dates (2046–2101 range observed) ^[sample e8573e97/exiftool.json]
Deploy / TTPs
| Capability | Evidence |
|---|---|
| Hidden VNC (HVNC) | HvncCommand, hvncThread, doHvnc, isDesktopCapturing ^[sample 667f1f97/strings.txt:5193-5984] |
| Browser credential cloning | CloneChrome, CloneFirefox, CloneEdge, CloneOpera, CloneBrave, CloneOperaGX ^[sample 667f1f97/strings.txt:4278-4624] |
| DPAPI secret decryption | Raton.Helper.DPAPI, DecryptPassword, Shit.DPapi ^[sample 667f1f97/strings.txt:4712-6093] |
| SQLite browser database access | SqliteMasterEntry, SqlStatement, ReadCookies, EatCookies ^[sample 667f1f97/strings.txt:7771-6959] |
| WiFi credential theft | WifiGrab ^[sample 667f1f97/strings.txt:4882] |
| Keystroke capture | HandleKeylogger, KeyCaptureLoop ^[sample 667f1f97/strings.txt:6698-7862] |
| Screen capture | SendScreenshot, capture screenshot (5 matches) ^[sample 667f1f97/capa.txt:151] |
| Clipboard hijack | CheckClipboard, LastClipboardText ^[sample 667f1f97/strings.txt:4196-7578] |
| Webcam/mic capture | HasCamera, HasMicrophone, SendCameraList, SendAudioSafe ^[sample 667f1f97/strings.txt:4855-5645] |
| RunPE process injection | HandleRunPE, DelegateVirtualAllocEx, DelegateWriteProcessMemory ^[sample 667f1f97/strings.txt:4690-7756] |
| UAC bypass | Commands.Handlers.UAC ^[sample 667f1f97/strings.txt:4645] |
| Registry Run persistence | persist via Run registry key (6 matches) ^[sample 667f1f97/capa.txt:275] |
| Scheduled task persistence | schedule task via schtasks (8 matches) ^[sample 667f1f97/capa.txt:277] |
| Anti-VM | QEMU, VMware, VirtualBox, Xen string references ^[sample 667f1f97/capa.txt:133-141] |
| Anti-debug | CheckRemoteDebuggerPresent, WudfIsAnyDebuggerPresent ^[sample 667f1f97/capa.txt:131-133] |
| Self-deletion | self delete (6 matches) ^[sample 667f1f97/capa.txt:132] |
| Defender tampering | disable Windows Defender features via registry on Windows ^[sample 667f1f97/capa.txt:264] |
| Ransomware/locker modules | Ransomware, LockScreen, InputBlock, Screamer, Jigsaw, WPro ^[sample 667f1f97/strings.txt:6936-6946] |
| C2 protocol | Async TCP client/server with HTTP fallback, Newtonsoft.Json serialization ^[sample 667f1f97/capa.txt:158-161] |
Variants / Aliases
- OpenCTI labels:
ratonrat(primary),clipbanker(feature-limited variant emphasizing clipboard hijacking),njrat(false positive on sample3f434324— no NJRat code artefacts observed) - Internal name:
clientForCrypters.exeacross all confirmed siblings - Namespace:
Client.Shit.Packaged/Client.Raton/Raton.Classes
Notable Analyses
667f1f97d015— 2.5 MB, .NET Framework 4.x, full capability set, no obfuscation ^[/intel/analyses/667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9.html]e8573e97c75b— 3.7 MB sibling, identical internal name,ratonratOpenCTI label ^[sample e8573e97/triage.json]58a919673d1c— 2.5 MB sibling,ratonratlabel ^[sample 58a91967/triage.json]9f21280ec273— 2.5 MB sibling,ratonratlabelda590d16a873— 2.6 MB sibling,ratonratlabel13dd71dc7122— 3.1 MB sibling,clipbankerlabel88a2c9db752d— 3.0 MB sibling,clipbankerlabele8c84a211316— 2.9 MB sibling,clipbankerlabel3f434324ac70— 3.7 MB sibling,njratlabel (false positive)fddc9cca767e— 2.5 MB sibling, no family label
Capabilities
hvnc-hidden-desktop-controlbrowser-credential-dpapi-clonesqlite-cookie-password-theftwifi-credential-harvestkeystroke-logging-hook-and-pollclipboard-monitor-hijackwebcam-directshow-capturemicrophone-naudio-capturescreenshot-winapi-capturerunpe-process-hollowinguac-bypass-handlerregistry-run-persistenceschtasks-scheduled-persistencedefender-registry-disableanti-vm-qemu-vmware-vbox-xenanti-debug-checkremotedebuggerpresentself-deletion-comspectcp-client-server-c2http-fallback-c2newtonsoft-json-serializationcostura-fody-il-mergingmodular-ransomware-locker-screamerasync-await-c2-supervisor
Related
- browser-credential-harvesting — cross-family credential theft concept
- raw-tcp-c2-socket — cross-family raw TCP C2 concept
- costura-fody-il-merging — build technique for dependency embedding
- dotnet-hvnc-hidden-desktop — HVNC technique page