Skip to main content
Mallory
MalwareUsed by 1 actor

Shadow RAT

Shadow RAT is a Windows remote access trojan offered through a live Malware-as-a-Service ecosystem. Breakglass Intelligence reported an operational Shadow RAT Panel v2.0 at 87.120.107[.]117 hosted on Shinomiya Hosting (AS215428), described as Ukrainian-operated bulletproof hosting. The panel used a Vite/React frontend with an Express.js backend and supported user registration, licensing, payload building, client management, and administration. Newly registered users required administrator approval, the user model included subscription-style license fields, and the service was linked to Telegram channels @spyingsystem and @CrackBaseProxy. The operator was identified in the reporting as Aleksei Ezhov.

The malware builder produced Windows RAT payloads with persistence, surveillance, credential theft, remote shell, and rootkit-related functionality. Reported persistence options included scheduled tasks, registry Run keys, and startup folder shortcuts. Additional capabilities included adding C:\ to Microsoft Defender exclusions, enabling a rootkit mode using the $77 file prefix, browser credential and cookie theft, Telegram session extraction, cryptocurrency wallet theft, remote control, and destructive actions including shutdown, reboot, BSOD, and self-delete.

Shadow RAT has also been associated with espionage activity. Malpedia and Seqrite Labs linked the malware family to UNG0002, a South Asian espionage actor. Seqrite documented Shadow RAT-related activity in Operation Cobalt Whisper and Operation AmberMist targeting defense, aviation, government, academia, and other strategic sectors in China, Hong Kong, and Pakistan during 2024–2025. In AmberMist, INET RAT was assessed as a customized variant of Shadow RAT. Reported infection chains used phishing emails, malicious ZIP archives, LNK shortcut files, and VBScript.

Known infrastructure and indicators mentioned in the content include the active panel at 87.120.107[.]117, a likely PostgreSQL server at 87.120.107[.]123:5432, and a previously known inactive Shadow RAT C2 at 5.9.228[.]188. An exposed phpinfo() page at http://87.120.107[.]117:8081/dashboard/phpinfo.php leaked host details including hostname DESKTOP-GKGI28A. A known Shadow RAT sample, mustang.dll, had SHA256 90c9e0ee1d74b596a0acf1e04b41c2c5f15d16b2acd39d3dc8f90b071888ac99 and reportedly used DLL sideloading via rasphone.exe with persistence through scheduled tasks named SysUpdater and UtilityUpdater.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNG0002

Breakglass Intelligence discovered a fully operational Shadow RAT command-and-control panel running at 87.120.107[.]117 on Ukrainian-operated bulletproof hosting infrastructure... The panel ... provides a complete Malware-as-a-Service platform with user registration, licensing, and a malware builder capable of producing Windows RAT payloads with rootkit, surveillance, credential theft, and remote shell capabilities.

via breakglass intelintel.breakglass.tech
MITRE ATT&CK

Techniques & procedures

24 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566.001Spearphishing AttachmentEvidence1

UNG0002 is characterized as a South Asian espionage actor with TTPs including spearphishing with weaponized documents... MITRE ATT&CK Mapping Tactic Technique ID Initial Access Spearphishing Attachment T1566.001

T1566.002Spearphishing LinkEvidence1

UNG0002 is characterized as a South Asian espionage actor with TTPs including ... fake government pages. MITRE ATT&CK Mapping ... Spearphishing Link T1566.002

Execution

4 techniques
T1053.005Scheduled TaskEvidence1

Persistence mechanisms include scheduled tasks via Windows Task Scheduler... Persistence is maintained through two scheduled tasks: SysUpdater and UtilityUpdater.

T1059.001PowerShellEvidence1
TacticExecution

MITRE ATT&CK Mapping Tactic Technique ID ... Execution PowerShell T1059.001

T1059.003Windows Command ShellEvidence1
TacticExecution

Remote Control : Interactive command shell (cmd.exe)... MITRE ATT&CK Mapping ... Execution Windows Command Shell T1059.003

T1204.002Malicious FileEvidence1
TacticExecution

The generated payload is then distributed to victims through the operator's chosen delivery method. MITRE ATT&CK Mapping ... Execution User Execution: Malicious File T1204.002

Persistence

2 techniques
T1053.005Scheduled TaskEvidence1

Persistence mechanisms include scheduled tasks via Windows Task Scheduler... Persistence is maintained through two scheduled tasks: SysUpdater and UtilityUpdater.

T1547.001Registry Run Keys / Startup FolderEvidence1

Persistence mechanisms include scheduled tasks via Windows Task Scheduler, registry run keys, and startup folder shortcuts. MITRE ATT&CK Mapping ... Persistence Registry Run Keys T1547.001

T1053.005Scheduled TaskEvidence1

Persistence mechanisms include scheduled tasks via Windows Task Scheduler... Persistence is maintained through two scheduled tasks: SysUpdater and UtilityUpdater.

T1547.001Registry Run Keys / Startup FolderEvidence1

Persistence mechanisms include scheduled tasks via Windows Task Scheduler, registry run keys, and startup folder shortcuts. MITRE ATT&CK Mapping ... Persistence Registry Run Keys T1547.001

Stealth

3 techniques
T1014RootkitEvidence1
TacticStealth

The builder can also add the entire C:\ drive to Windows Defender exclusions and enable a rootkit mode using the $77 file prefix, which requires administrator privileges or UAC bypass.

T1036.005Match Legitimate Resource Name or LocationEvidence1
TacticStealth

Payload options include ... assembly copy (cloning PE metadata from a donor executable for masquerading), icon injection for custom executable icons... MITRE ATT&CK Mapping ... Defense Evasion Masquerading T1036.005

T1070.004File DeletionEvidence1
TacticStealth

Payload options include melt-build (self-delete of the original executable after installation)... MITRE ATT&CK Mapping ... Defense Evasion File Deletion T1070.004

Credential Access

4 techniques
T1056.001KeyloggingEvidence1

The monitor feature also captures mouse and keyboard input... MITRE ATT&CK Mapping ... Collection Keylogging T1056.001

T1528Steal Application Access TokenEvidence1

Data Theft : Telegram session extraction... MITRE ATT&CK Mapping ... Credential Access Steal Application Access Token T1528

T1539Steal Web Session CookieEvidence1

Data Theft : ... browser cookie theft... MITRE ATT&CK Mapping ... Credential Access Steal Web Session Cookie T1539

T1555.003Credentials from Web BrowsersEvidence1

Data Theft : ... browser credential theft... MITRE ATT&CK Mapping ... Credential Access Credentials from Web Browsers T1555.003

Discovery

2 techniques
T1057Process DiscoveryEvidence1
TacticDiscovery

Remote Control : ... process manager with kill functionality... MITRE ATT&CK Mapping ... Discovery Process Discovery T1057

T1082System Information DiscoveryEvidence1
TacticDiscovery

MITRE ATT&CK Mapping ... Discovery System Information Discovery T1082

Collection

4 techniques
T1056.001KeyloggingEvidence1

The monitor feature also captures mouse and keyboard input... MITRE ATT&CK Mapping ... Collection Keylogging T1056.001

T1113Screen CaptureEvidence1

Surveillance : Real-time screen streaming with configurable quality and FPS, single-frame screenshot capture... MITRE ATT&CK Mapping ... Collection Screen Capture T1113

T1123Audio CaptureEvidence1

Surveillance : ... microphone recording. MITRE ATT&CK Mapping ... Collection Audio Capture T1123

T1125Video CaptureEvidence1

Surveillance : ... webcam access... MITRE ATT&CK Mapping ... Collection Video Capture T1125

T1071.001Web ProtocolsEvidence1

C2 traffic patterns : HTTP traffic to 87.120.107[.]117 with Express.js headers... MITRE ATT&CK Mapping ... Command and Control Web Protocols T1071.001

T1105Ingress Tool TransferEvidence1

Remote Control : ... URL-based download-and-execute... MITRE ATT&CK Mapping ... Command and Control Ingress Tool Transfer T1105

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

MITRE ATT&CK Mapping ... Exfiltration Exfiltration Over C2 Channel T1041

Impact

1 technique
T1529System Shutdown/RebootEvidence1
TacticImpact

Destructive : System restart, shutdown, BSOD trigger, and self-delete. MITRE ATT&CK Mapping ... Impact System Shutdown/Reboot T1529

Other

1 technique
T1562.001Disable or Modify ToolsEvidence1

The builder can also add the entire C:\ drive to Windows Defender exclusions... MITRE ATT&CK Mapping ... Defense Evasion Disable or Modify Tools T1562.001

INDICATORS OF COMPROMISE

IOCs tracked for this family

18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
9 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
4 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
5 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in app3 months ago
hash.sha1●●●●●●●●●●●●View more in app3 months ago
ip.v4●●●●●●●●●●●●View more in app3 months ago
ip.v4●●●●●●●●●●●●View more in app3 months ago
ip.v4●●●●●●●●●●●●View more in app3 months ago
uri●●●●●●●●●●●●View more in app3 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching18

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping24

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.