Cyber Security

New Millenium RAT Sold on GitHub Attacking Windows Systems

Millenium-RAT, a sophisticated Remote Access Tool (RAT) for Windows systems, is now available for purchase on GitHub, which exclusively attacking windows systems.

The Millenium-RAT, particularly version 2.4; is a Win32 executable built on the.NET framework. It is intended to covertly retrieve a vast quantity of data from systems that have been compromised.

Millenium RAT’s evolution from version 2.4 to the most recent version 2.5 highlights its dynamic threat landscape and ongoing development and release.

The Millennium Rat as A Growing Threat

CYFIRMA says this malware is a great example of a complex set of malicious features carefully designed to steal sensitive user data, stay on a device even when cutting-edge anti-analysis techniques try to find it, become persistent, and give hackers remote control over the infected device.

With its wide range of abilities, the Millenium-RAT-2.4 can be used for data exfiltration, system information gathering, process disruption, self-destruct mechanisms, evasion strategies in sandbox settings, anti-debugging measures, and remote command execution over the Telegram platform.

On GitHub, this RAT is being advertised under false pretenses of being an educational resource, all the while secretly providing lifetime access for a small cost. 

Although the project is closed source and the code is unavailable to the public, those interested are asked to contact the project over Telegram to gain access.

The examined sample below is from version 2.4, which the malware creator revealed on their GitHub account is accessible for lifetime access for $30.

Sample from version 2.4, available for a lifetime access at $30

Additionally, there is the RAT builder, which provides customization options to enable the building of the RAT specifically customized to meet requirements. Users can submit information like the Telegram chat ID, the Telegram Bot token, and even specific filenames, like the keylogger file.

Researchers say the Millenium RAT looks to be a derivative of the ToxicEye RAT, an open-source Telegram RAT. The structure, modules, code, namespaces, function names, and arguments of MilleniumRAT and ToxicEye RATs are similar.

The structure and modules of MilleniumRAT and ToxicEye RATs are the same.

This implies that attackers may modify and reuse already-existing open-source malicious code to fit their purposes, posing a significant threat to cybersecurity environments.

Millenium Rat Presents a Significant Risk To Cybersecurity

The appearance of malware such as Millenium RAT, notable for its multifunctionality and ability to steal a vast amount of data from compromised systems, is a major cybersecurity threat.

The RAT uses several strategies, such as evasion, persistence, and granting remote control over compromised computers.

“The provision of a RAT builder allows customization, where users can choose features and parameters such as Telegram details and filenames, denoting the alarming ease with which these malicious tools can be manipulated and distributed”, researchers said.

Therefore, it is recommended that stakeholders enhance and strengthen their cybersecurity posture to effectively tackle these diverse threats.

Balaji N

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

1 hour ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

1 hour ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

2 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

3 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

3 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

4 hours ago