Skip to main content
Mallory
MalwareUsed by 1 actor

WmRAT

WmRAT is a C++ malware family associated with the Bitter threat actor, also tracked as TA397, which Proofpoint and Threatray assessed with high confidence as a state-backed espionage group aligned with Indian government interests. Reporting from late 2024 through early 2025 places WmRAT in campaigns targeting primarily government, diplomatic, and defense organizations, including targeting of Turkey and entities in Europe with links to China and neighboring countries relevant to Indian geopolitical interests. Proofpoint reported that TA397 used spear-phishing as the observed initial access vector, delivering files or URLs that commonly created scheduled tasks; the actor experimented with MSC, CHM, LNK, IQY, and Microsoft Access files, and in some cases abused Microsoft Search Connector files and exploited CVE-2024-43572 (GrimResource). In hands-on-keyboard intrusions against government organizations, TA397 manually enumerated victim systems and selectively deployed follow-on payloads including WmRAT and MiyaRAT, sometimes after pre-filtering targets based on received system information. Proofpoint found WmRAT payloads on a TA397-controlled SMB share after operators mounted \72.18.215[.]1\tempy to retrieve payloads. Detection content indicates WmRAT can be tracked via YARA using socket usage, error handling, and reused strings. High-confidence infrastructure and related indicators mentioned in the reporting include TA397 upload activity to /svupfl.php on 46.229.55[.]63, attempted payload retrieval from 173.254.204[.]72, and the SMB share \72.18.215[.]1\tempy where WmRAT and MiyaRAT payloads were found.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Bitter

In December 2024, evidence emerged of the threat actor's targeting of Turkey using malware families such as WmRAT and MiyaRAT...

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

"PLAYFULGHOST Delivered via Phishing and SEO Poisoning"; "Victims get infected via phishing emails"; "phishing campaign" (multiple entries)

Execution

1 technique
T1053.005Scheduled TaskEvidence1

"created a scheduled task on the target machine to pull down further payloads"

Persistence

1 technique
T1053.005Scheduled TaskEvidence1

"created a scheduled task on the target machine to pull down further payloads"

T1053.005Scheduled TaskEvidence1

"created a scheduled task on the target machine to pull down further payloads"

Stealth

1 technique
T1564.004NTFS File AttributesEvidence1
TacticStealth

"used alternate data streams in a RAR archive"

T1105Ingress Tool TransferEvidence1

"EAGERBEE ... deploy additional payloads"; "download and execute malware code"; "pull down further payloads"

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.