njRAT

S0385

Malware.View on attack.mitre.org

About this malware

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.

Techniques used31

Procedure examples31

TechniqueProcedure example
T1005
Data from Local System

njRAT can collect data from a local system.

T1010
Application Window Discovery

njRAT gathers information about opened windows during the initial infection.

T1012
Query Registry

njRAT can read specific registry values.

T1018
Remote System Discovery

njRAT can identify remote hosts on connected networks.

T1021.001
Remote Desktop Protocol

njRAT has a module for performing remote desktop access.

T1027.004
Compile After Delivery

njRAT has used AutoIt to compile the payload and main script into a single executable after delivery.

T1027.013
Encrypted/Encoded File

njRAT has included a base64 encoded executable.

T1033
System Owner/User Discovery

njRAT enumerates the current user during the initial infection.

T1041
Exfiltration Over C2 Channel

njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information.

T1056.001
Keylogging

njRAT is capable of logging keystrokes.

T1057
Process Discovery

njRAT can search a list of running processes for Tr.exe.

T1059.001
PowerShell

njRAT has executed PowerShell commands via auto-run registry key persistence.

T1059.003
Windows Command Shell

njRAT can launch a command shell interface for executing commands.

T1070.004
File Deletion

njRAT is capable of deleting files.

T1070.009
Clear Persistence

njRAT is capable of manipulating and deleting registry keys, including those used for persistence.

View all 31 procedure examples

Groups that use it8

Campaigns1

References1

  1. Fidelis njRAT June 2013 Open source
    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.