Skip to main content

Millenium: A RAT Rewritten, A Threat Multiplied

0
Medium
Published: 06/25/2026 (06/25/2026, 18:43:48 UTC)
Source: AlienVault OTX General

Description

Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone significant architectural changes from .NET to native C++, while continuing to leverage Telegram Bot API for command and control without requiring dedicated server infrastructure. The malware is distributed as Malware-as-a-Service by developer 'ShinyEnigma' for $50-90 USD. Active exploitation campaigns are conducted by threat actor cluster 'Y2K Operators' using social engineering tactics including fraudulent utilities, hacking toolkits, software cracks, gaming lures, and trojanized cybercrime tools. The trojan enables exfiltration of sensitive browser and system data, screenshot and audio capture, keylogging, and arbitrary executable downloads. Over 62,000 compromised endpoints across more than 160 countries have been identified, with 39,730 infections occurring in Q1 2026 alone, demonstrating accelerating infection rates.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 12:45:30 UTC

Technical Analysis

Millenium RAT 4.* is a remote access trojan that has been significantly re-engineered from a .NET framework to native C++ while maintaining its use of the Telegram Bot API for command and control, eliminating the need for dedicated C2 servers. It is sold as Malware-as-a-Service by 'ShinyEnigma' and exploited by the 'Y2K Operators' group through social engineering vectors including fake utilities and trojanized cybercrime tools. The malware facilitates comprehensive data theft and system surveillance capabilities, including keylogging, screenshot and audio capture, and arbitrary code execution. The infection scale is global, with over 62,000 compromised endpoints identified across more than 160 countries, and infection rates are increasing rapidly. There is no indication of a software vulnerability or patch; this is a malware threat distributed via social engineering and user compromise.

Potential Impact

The malware enables attackers to exfiltrate sensitive browser and system data, capture screenshots and audio, log keystrokes, and execute arbitrary code on infected systems. This can lead to significant data breaches, privacy violations, and potential further compromise of affected networks. The widespread infections and rapid growth in compromised endpoints demonstrate a substantial operational impact on victims worldwide.

Defensive Guidance

No official patch or remediation is available as this is malware distributed via social engineering rather than exploiting a software vulnerability. Defenders should focus on user education to recognize social engineering tactics, employ endpoint protection solutions capable of detecting and blocking Millenium RAT, and monitor for indicators of compromise. Since the malware uses Telegram Bot API for C2, network monitoring for suspicious Telegram API traffic may assist detection. There is no vendor-managed remediation or official fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/millenium-rat-maas/"]
Adversary
Y2K Operators
Pulse Id
6a3d76e592eaea08a66ad337

Indicators of Compromise

Ip

ValueDescriptionCopy
ip62.60.226.97
—
ip130.12.180.43
—
ip158.94.208.168
—

Url

ValueDescriptionCopy
urlhttps://blackhatusa.com/update.exe
—
urlhttps://blackhatusa.com/clip.exe
—
urlhttps://blackhatusa.com/setup.exe
—
urlhttp://130.12.180.43/files/7924412375/upOSLDn.exe
—
urlhttp://158.94.208.168/files/8514679081/DRTjyu7.exe
—
urlhttp://blackhatusa.com/mr.exe
—
urlhttp://kuttabilla.top/mr.exe
—
urlhttps://75877.mcdir.me/files/2.vbs
—
urlhttps://75877.mcdir.me/files/doc1.exe
—
urlhttps://milleniumrat.online
—
urlhttps://modedapk.net/update1.exe
—
urlhttps://www.thesnapchatmodapk.com/update1.exe
—

Domain

ValueDescriptionCopy
domainblackhatusa.com
—
domainmodedapk.net
—
domainkuttabilla.top
—
domainmilleniumrat.online
—
domain75877.mcdir.me
—
domainwww.thesnapchatmodapk.com
—

Hash

ValueDescriptionCopy
hash7b6473f036225bc35da89e5049ae55ba
—
hashddbc1037925f7d6c07a9ddbe38286a2fcedc4890
—
hashccca11a6d5835999c40a0a5264084b3740633600c157754fad2ef59559e31736
—
hasha1c160243efd54a9bf00655966971aae
—
hashcc2c9d90ffba060c9521d40776ffaa907ecec2bb
—
hash512adab2c69feaf026adfb12cbd7d2eb4fee746120491e44f476eebddcbb19f2
—
hash66bf111030a2e22db575c0b7b7b677208745eef8b44265bb4259f41f126f1bf8
—
hash7d8b6a64f7b65b281e7b5568929c6f96c62bbae9628162aabe7d8140a86d3de8
—
hash754ba4fb2e083944f84ba50b90ddda87
—
hashf27b08a8347e1ba84a61fbfe58edcb8f84d06642
—
hash5a23ca644cb1f310be1abd5f6c6a3b3e15681ced99b0947a7f3465a79aae5089
—
hash8f8a71352d2f18162f2f74090dc6f0cae6b37029e3244e6522825ade75163055
—
hasha8acc24bb3e6a1a3b66a31ceaefda07d4a0e17415468683458b499f2ba240450
—
hashd55ce447e249ef9045750865fa196c8ca8434c8c484f861b7bdecbceeab7c16e
—
hashad0f892b7b99b68491ade4949ef6b575e64d9df5f84a53019b5c1e4eeb4c46a9
—
hash1d699a46339626db299548e32ed3a77eec267840c3de39b49caf38b88aeb150d
—
hash066576554f9eff84eaa415a4bd012b2e
—
hash07a364ba1b34d0b04bb68872006d9615
—
hash195d1c56f35d7a8d38e2ab0cdc1fa8cd
—
hash1ef2f666b543293aaec55d10fbc4bc46
—
hash35af4c61ce04f0c0796baf5831e2ef24
—
hash35dfec976f6fd85f76d011d0075b5926
—
hash3c1032e271dd885e912a79c67f2855e7
—
hash4f32d85224309688c600c21865294717
—
hash52deca7016315faf844f0ba0d754027e
—
hash53e78d1fef04a39353a7dbc19f8ac86d
—
hash6dc5e2f50900ba1e7a4ee87f950fa409
—
hash87e06d8cec9cf7c2808d17c836089053
—
hash89aa2ce1978f3386f9ee433515e457b1
—
hasha0503abcebf054a006fd4436a73c2dd7
—
hashb82f0480f6403174120f99cdceab83e0
—
hashc704ad8e3fe023e03c4ca07973bd6e78
—
hashd456b165eda38d5d591db9b1bf913463
—
hashf4281c571efa6e0453cf9878a21bb587
—
hash28fbbe5cadb2f4a236acd1977c58bcb7877226e8
—
hash34366f3c17d26856028b472dd8d433913eb2c935
—
hash5a416890fdb135b3c94a70055273d69d48dc6e7f
—
hash73a5a94c1222fd333bf3be1322dd09e896159f1a
—
hash76330efb09c3355f7547e78cde1c1a0d1f332cb6
—
hash7fad85e9e2c6641498e7c7df4357498b734e3a26
—
hash9d858418c57b513908bba61cb081fbf5914d233a
—
hasha684f8c4e1759e4b3cd18d7e3a248d79e4616875
—
hashb1235ce53ef2a09253f7a212369ae2fef1edde4c
—
hashb8370381539c085772d3b7503d39573fc7c24ebc
—
hashd826b2a24fa3c9b94efd9a33eac7ab2e71abd2c0
—
hashdcff6378b57b6a8ac664254102c656affc62ac49
—
hashe3af48f83557fce9f3dbdc557fa126720ea87983
—
hashe3c0c8761e15442408fc354262c1e206beb4e11f
—
hasheb8d7b899ae946face81d88edbacb3e4d2b4ded4
—
hashee9f060b7446336fc9252d2c639ab6e62f324bfe
—
hasheff1f644e6006d8a8229d22836f7298930db08ac
—
hashfae763674667e007e8287d56b7aa398ac3d66d77
—
hash12b41c07299d2535f7cdc194d97496acd944a9eb5d94b8d24b19291ed9d0830c
—
hash19e0070e5009bd5b376b9be997361d0773dcb004200ee8fafe6c14b96cbd93e4
—
hash1c01ab1b59245f24ebdc5d9c414fcf4e2ce31f71f181522efc5a3d27476c8e21
—
hash1d52ded1f3838a1eee849ae20b2fee6c84b183cc98abe7244365b9f34b925eea
—
hash2267d05dbd5e30c6dfcdde25731280dd755e689faa684bd21cfbef5281fd3e86
—
hash2d5615acd1b0666995fd124fb72f2713c6609b5368350340288b52fecbdd016d
—
hash2d8e5a2763f9a899fda44390d5b8495836c11fb266a61868d52d1f397c5243ee
—
hash307964ed02f34bff4e40c5402cc936be07fd9957ef400596a4b3e2cd98c50ec1
—
hash3e17ce0b30b9fd6863b341ae58ee118dc13f2ee7f1c92ac4b81c04d54480d0e0
—
hash4991873515d6dea70d7769cf67ccd8ea69184e5e454a6e6d1e093b6a3c48eb47
—
hash4e035575be8fe350a9e36cf29dbbc8826af2f772672bd08c9e489a243cb90e31
—
hash5562246e38f8935ba8b07350e6aaa44bc22abf37b77f49836fde5999f4b61cf1
—
hash57edeb575862ce8d3bff2eb4d32d9e3fa1ffb7cb8f818e2e7fc6d25a506faea6
—
hash7a370a9262d37de6a24706f92ff0cdded7202281a6ff3bf313721756226ebff9
—
hash8419b1f0acca46d45f4c54c315c8cc4784946e07d547fe55187b928fa6c6b8f5
—
hash848036661c71b80ee41566918faa5eae3bf4f03ae807bb4af42cb483b6c141e2
—
hash85816d89dac648645a9026973772815e956c267232b3d2577a06a43418f19ed3
—
hash88f9e169a85dcf6a1c03bf3ca1b1a262ed32baeca46cb87f0324adfdc098d4a2
—
hash8bef879c6920cdce7c01b8dbb7da24dca23b8822a7aa00dfc72cb32f55879a24
—
hash92710bdb44279dbe8ccff34ba698d1558fa6d271c99ed4960ccbfb6d518d9418
—
hasha4b34b94a905fe330b0a3e4502aa45356e383a8f45ff1d008b785ea0ec14acaf
—
hasha911fe0259772906447d7e80a902ea954f3530edd9ea7d0427b6380707a8e681
—
hasha97f15d7bfad02a600eba426c3ef72be34e944a7c8364a975c53866735f7aa4e
—
hashaa2ccd18a7a09f66ca5c1bbd927f7fe411bd3874df77b0eaf40738dab7566606
—
hashad74f502cc37e815482df49f118b2f678daf1a3f522daf07a2abeb32c2ed3831
—
hashcc47209d2e4d5a9b2b1d71622b0ad7f73e9c4aa56edd9aaf1e29265650c30f16
—
hashde3842bbb6626912d5b9b01fb775e1843004edb5855d4e627fd74b88bc7fe33b
—
hashe4496565d9fd2f9425c10a98d3a8632c12af5fe4259484cb202d7f65532b7df2
—
hashfc41c336b79cbc6559a17d716b84101dbef1adc5357b643a75111af442719611
—

Threat ID: 6a3e38cb4853345fc184bae6

Added to database: 06/26/2026, 08:31:07 UTC

Last enriched: 07/31/2026, 12:45:30 UTC

Last updated: 09/24/2026, 19:36:03 UTC

Views: 394

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses