WmRAT
WmRAT is a C++ malware family associated with the Bitter threat actor, also tracked as TA397, which Proofpoint and Threatray assessed with high confidence as a state-backed espionage group aligned with Indian government interests. Reporting from late 2024 through early 2025 places WmRAT in campaigns targeting primarily government, diplomatic, and defense organizations, including targeting of Turkey and entities in Europe with links to China and neighboring countries relevant to Indian geopolitical interests. Proofpoint reported that TA397 used spear-phishing as the observed initial access vector, delivering files or URLs that commonly created scheduled tasks; the actor experimented with MSC, CHM, LNK, IQY, and Microsoft Access files, and in some cases abused Microsoft Search Connector files and exploited CVE-2024-43572 (GrimResource). In hands-on-keyboard intrusions against government organizations, TA397 manually enumerated victim systems and selectively deployed follow-on payloads including WmRAT and MiyaRAT, sometimes after pre-filtering targets based on received system information. Proofpoint found WmRAT payloads on a TA397-controlled SMB share after operators mounted \72.18.215[.]1\tempy to retrieve payloads. Detection content indicates WmRAT can be tracked via YARA using socket usage, error handling, and reused strings. High-confidence infrastructure and related indicators mentioned in the reporting include TA397 upload activity to /svupfl.php on 46.229.55[.]63, attempted payload retrieval from 173.254.204[.]72, and the SMB share \72.18.215[.]1\tempy where WmRAT and MiyaRAT payloads were found.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In December 2024, evidence emerged of the threat actor's targeting of Turkey using malware families such as WmRAT and MiyaRAT...
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique"PLAYFULGHOST Delivered via Phishing and SEO Poisoning"; "Victims get infected via phishing emails"; "phishing campaign" (multiple entries)
Execution
1 techniquePersistence
1 techniquePrivilege Escalation
1 techniqueStealth
1 techniqueCommand and Control
1 technique"EAGERBEE ... deploy additional payloads"; "download and execute malware code"; "pull down further payloads"
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ malware family used in an espionage intrusion against a Turkish defense-sector organization.
Remote access trojan used by Bitter/TA397 in targeting activity (Turkey noted) as part of an espionage-focused toolset.
wmRAT is a remote access trojan (RAT) deployed by TA397 for hands-on-keyboard access, enabling remote control and data exfiltration from victim systems.
Remote access trojan (RAT) tracked via a new YARA rule; detection focuses on socket usage, error handling, and reused strings.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.