Millenium: A RAT Rewritten, A Threat Multiplied
Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone significant architectural changes from .NET to native C++, while continuing to leverage Telegram Bot API for command and control without requiring dedicated server infrastructure. The malware is distributed as Malware-as-a-Service by developer 'ShinyEnigma' for $50-90 USD. Active exploitation campaigns are conducted by threat actor cluster 'Y2K Operators' using social engineering tactics including fraudulent utilities, hacking toolkits, software cracks, gaming lures, and trojanized cybercrime tools. The trojan enables exfiltration of sensitive browser and system data, screenshot and audio capture, keylogging, and arbitrary executable downloads. Over 62,000 compromised endpoints across more than 160 countries have been identified, with 39,730 infections occurring in Q1 2026 alone, demonstrating accelerating infection rates.
AI Analysis
Technical Summary
Millenium RAT 4.* is a remote access trojan that has been significantly re-engineered from a .NET framework to native C++ while maintaining its use of the Telegram Bot API for command and control, eliminating the need for dedicated C2 servers. It is sold as Malware-as-a-Service by 'ShinyEnigma' and exploited by the 'Y2K Operators' group through social engineering vectors including fake utilities and trojanized cybercrime tools. The malware facilitates comprehensive data theft and system surveillance capabilities, including keylogging, screenshot and audio capture, and arbitrary code execution. The infection scale is global, with over 62,000 compromised endpoints identified across more than 160 countries, and infection rates are increasing rapidly. There is no indication of a software vulnerability or patch; this is a malware threat distributed via social engineering and user compromise.
Potential Impact
The malware enables attackers to exfiltrate sensitive browser and system data, capture screenshots and audio, log keystrokes, and execute arbitrary code on infected systems. This can lead to significant data breaches, privacy violations, and potential further compromise of affected networks. The widespread infections and rapid growth in compromised endpoints demonstrate a substantial operational impact on victims worldwide.
Mitigation Recommendations
No official patch or remediation is available as this is malware distributed via social engineering rather than exploiting a software vulnerability. Defenders should focus on user education to recognize social engineering tactics, employ endpoint protection solutions capable of detecting and blocking Millenium RAT, and monitor for indicators of compromise. Since the malware uses Telegram Bot API for C2, network monitoring for suspicious Telegram API traffic may assist detection. There is no vendor-managed remediation or official fix.
Indicators of Compromise
- ip: 62.60.226.97
- url: https://blackhatusa.com/update.exe
- url: https://blackhatusa.com/clip.exe
- url: https://blackhatusa.com/setup.exe
- domain: blackhatusa.com
- hash: 7b6473f036225bc35da89e5049ae55ba
- hash: ddbc1037925f7d6c07a9ddbe38286a2fcedc4890
- hash: ccca11a6d5835999c40a0a5264084b3740633600c157754fad2ef59559e31736
- hash: a1c160243efd54a9bf00655966971aae
- hash: cc2c9d90ffba060c9521d40776ffaa907ecec2bb
- hash: 512adab2c69feaf026adfb12cbd7d2eb4fee746120491e44f476eebddcbb19f2
- ip: 130.12.180.43
- hash: 66bf111030a2e22db575c0b7b7b677208745eef8b44265bb4259f41f126f1bf8
- url: http://130.12.180.43/files/7924412375/upOSLDn.exe
- hash: 7d8b6a64f7b65b281e7b5568929c6f96c62bbae9628162aabe7d8140a86d3de8
- hash: 754ba4fb2e083944f84ba50b90ddda87
- hash: f27b08a8347e1ba84a61fbfe58edcb8f84d06642
- hash: 5a23ca644cb1f310be1abd5f6c6a3b3e15681ced99b0947a7f3465a79aae5089
- hash: 8f8a71352d2f18162f2f74090dc6f0cae6b37029e3244e6522825ade75163055
- hash: a8acc24bb3e6a1a3b66a31ceaefda07d4a0e17415468683458b499f2ba240450
- hash: d55ce447e249ef9045750865fa196c8ca8434c8c484f861b7bdecbceeab7c16e
- hash: ad0f892b7b99b68491ade4949ef6b575e64d9df5f84a53019b5c1e4eeb4c46a9
- ip: 158.94.208.168
- hash: 1d699a46339626db299548e32ed3a77eec267840c3de39b49caf38b88aeb150d
- url: http://158.94.208.168/files/8514679081/DRTjyu7.exe
- domain: modedapk.net
- hash: 066576554f9eff84eaa415a4bd012b2e
- hash: 07a364ba1b34d0b04bb68872006d9615
- hash: 195d1c56f35d7a8d38e2ab0cdc1fa8cd
- hash: 1ef2f666b543293aaec55d10fbc4bc46
- hash: 35af4c61ce04f0c0796baf5831e2ef24
- hash: 35dfec976f6fd85f76d011d0075b5926
- hash: 3c1032e271dd885e912a79c67f2855e7
- hash: 4f32d85224309688c600c21865294717
- hash: 52deca7016315faf844f0ba0d754027e
- hash: 53e78d1fef04a39353a7dbc19f8ac86d
- hash: 6dc5e2f50900ba1e7a4ee87f950fa409
- hash: 87e06d8cec9cf7c2808d17c836089053
- hash: 89aa2ce1978f3386f9ee433515e457b1
- hash: a0503abcebf054a006fd4436a73c2dd7
- hash: b82f0480f6403174120f99cdceab83e0
- hash: c704ad8e3fe023e03c4ca07973bd6e78
- hash: d456b165eda38d5d591db9b1bf913463
- hash: f4281c571efa6e0453cf9878a21bb587
- hash: 28fbbe5cadb2f4a236acd1977c58bcb7877226e8
- hash: 34366f3c17d26856028b472dd8d433913eb2c935
- hash: 5a416890fdb135b3c94a70055273d69d48dc6e7f
- hash: 73a5a94c1222fd333bf3be1322dd09e896159f1a
- hash: 76330efb09c3355f7547e78cde1c1a0d1f332cb6
- hash: 7fad85e9e2c6641498e7c7df4357498b734e3a26
- hash: 9d858418c57b513908bba61cb081fbf5914d233a
- hash: a684f8c4e1759e4b3cd18d7e3a248d79e4616875
- hash: b1235ce53ef2a09253f7a212369ae2fef1edde4c
- hash: b8370381539c085772d3b7503d39573fc7c24ebc
- hash: d826b2a24fa3c9b94efd9a33eac7ab2e71abd2c0
- hash: dcff6378b57b6a8ac664254102c656affc62ac49
- hash: e3af48f83557fce9f3dbdc557fa126720ea87983
- hash: e3c0c8761e15442408fc354262c1e206beb4e11f
- hash: eb8d7b899ae946face81d88edbacb3e4d2b4ded4
- hash: ee9f060b7446336fc9252d2c639ab6e62f324bfe
- hash: eff1f644e6006d8a8229d22836f7298930db08ac
- hash: fae763674667e007e8287d56b7aa398ac3d66d77
- hash: 12b41c07299d2535f7cdc194d97496acd944a9eb5d94b8d24b19291ed9d0830c
- hash: 19e0070e5009bd5b376b9be997361d0773dcb004200ee8fafe6c14b96cbd93e4
- hash: 1c01ab1b59245f24ebdc5d9c414fcf4e2ce31f71f181522efc5a3d27476c8e21
- hash: 1d52ded1f3838a1eee849ae20b2fee6c84b183cc98abe7244365b9f34b925eea
- hash: 2267d05dbd5e30c6dfcdde25731280dd755e689faa684bd21cfbef5281fd3e86
- hash: 2d5615acd1b0666995fd124fb72f2713c6609b5368350340288b52fecbdd016d
- hash: 2d8e5a2763f9a899fda44390d5b8495836c11fb266a61868d52d1f397c5243ee
- hash: 307964ed02f34bff4e40c5402cc936be07fd9957ef400596a4b3e2cd98c50ec1
- hash: 3e17ce0b30b9fd6863b341ae58ee118dc13f2ee7f1c92ac4b81c04d54480d0e0
- hash: 4991873515d6dea70d7769cf67ccd8ea69184e5e454a6e6d1e093b6a3c48eb47
- hash: 4e035575be8fe350a9e36cf29dbbc8826af2f772672bd08c9e489a243cb90e31
- hash: 5562246e38f8935ba8b07350e6aaa44bc22abf37b77f49836fde5999f4b61cf1
- hash: 57edeb575862ce8d3bff2eb4d32d9e3fa1ffb7cb8f818e2e7fc6d25a506faea6
- hash: 7a370a9262d37de6a24706f92ff0cdded7202281a6ff3bf313721756226ebff9
- hash: 8419b1f0acca46d45f4c54c315c8cc4784946e07d547fe55187b928fa6c6b8f5
- hash: 848036661c71b80ee41566918faa5eae3bf4f03ae807bb4af42cb483b6c141e2
- hash: 85816d89dac648645a9026973772815e956c267232b3d2577a06a43418f19ed3
- hash: 88f9e169a85dcf6a1c03bf3ca1b1a262ed32baeca46cb87f0324adfdc098d4a2
- hash: 8bef879c6920cdce7c01b8dbb7da24dca23b8822a7aa00dfc72cb32f55879a24
- hash: 92710bdb44279dbe8ccff34ba698d1558fa6d271c99ed4960ccbfb6d518d9418
- hash: a4b34b94a905fe330b0a3e4502aa45356e383a8f45ff1d008b785ea0ec14acaf
- hash: a911fe0259772906447d7e80a902ea954f3530edd9ea7d0427b6380707a8e681
- hash: a97f15d7bfad02a600eba426c3ef72be34e944a7c8364a975c53866735f7aa4e
- hash: aa2ccd18a7a09f66ca5c1bbd927f7fe411bd3874df77b0eaf40738dab7566606
- hash: ad74f502cc37e815482df49f118b2f678daf1a3f522daf07a2abeb32c2ed3831
- hash: cc47209d2e4d5a9b2b1d71622b0ad7f73e9c4aa56edd9aaf1e29265650c30f16
- hash: de3842bbb6626912d5b9b01fb775e1843004edb5855d4e627fd74b88bc7fe33b
- hash: e4496565d9fd2f9425c10a98d3a8632c12af5fe4259484cb202d7f65532b7df2
- hash: fc41c336b79cbc6559a17d716b84101dbef1adc5357b643a75111af442719611
- url: http://blackhatusa.com/mr.exe
- url: http://kuttabilla.top/mr.exe
- url: https://75877.mcdir.me/files/2.vbs
- url: https://75877.mcdir.me/files/doc1.exe
- url: https://milleniumrat.online
- url: https://modedapk.net/update1.exe
- url: https://www.thesnapchatmodapk.com/update1.exe
- domain: kuttabilla.top
- domain: milleniumrat.online
- domain: 75877.mcdir.me
- domain: www.thesnapchatmodapk.com
Millenium: A RAT Rewritten, A Threat Multiplied
Description
Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone significant architectural changes from .NET to native C++, while continuing to leverage Telegram Bot API for command and control without requiring dedicated server infrastructure. The malware is distributed as Malware-as-a-Service by developer 'ShinyEnigma' for $50-90 USD. Active exploitation campaigns are conducted by threat actor cluster 'Y2K Operators' using social engineering tactics including fraudulent utilities, hacking toolkits, software cracks, gaming lures, and trojanized cybercrime tools. The trojan enables exfiltration of sensitive browser and system data, screenshot and audio capture, keylogging, and arbitrary executable downloads. Over 62,000 compromised endpoints across more than 160 countries have been identified, with 39,730 infections occurring in Q1 2026 alone, demonstrating accelerating infection rates.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Millenium RAT 4.* is a remote access trojan that has been significantly re-engineered from a .NET framework to native C++ while maintaining its use of the Telegram Bot API for command and control, eliminating the need for dedicated C2 servers. It is sold as Malware-as-a-Service by 'ShinyEnigma' and exploited by the 'Y2K Operators' group through social engineering vectors including fake utilities and trojanized cybercrime tools. The malware facilitates comprehensive data theft and system surveillance capabilities, including keylogging, screenshot and audio capture, and arbitrary code execution. The infection scale is global, with over 62,000 compromised endpoints identified across more than 160 countries, and infection rates are increasing rapidly. There is no indication of a software vulnerability or patch; this is a malware threat distributed via social engineering and user compromise.
Potential Impact
The malware enables attackers to exfiltrate sensitive browser and system data, capture screenshots and audio, log keystrokes, and execute arbitrary code on infected systems. This can lead to significant data breaches, privacy violations, and potential further compromise of affected networks. The widespread infections and rapid growth in compromised endpoints demonstrate a substantial operational impact on victims worldwide.
Defensive Guidance
No official patch or remediation is available as this is malware distributed via social engineering rather than exploiting a software vulnerability. Defenders should focus on user education to recognize social engineering tactics, employ endpoint protection solutions capable of detecting and blocking Millenium RAT, and monitor for indicators of compromise. Since the malware uses Telegram Bot API for C2, network monitoring for suspicious Telegram API traffic may assist detection. There is no vendor-managed remediation or official fix.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/millenium-rat-maas/"]
- Adversary
- Y2K Operators
- Pulse Id
- 6a3d76e592eaea08a66ad337
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip62.60.226.97 | — | |
ip130.12.180.43 | — | |
ip158.94.208.168 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://blackhatusa.com/update.exe | — | |
urlhttps://blackhatusa.com/clip.exe | — | |
urlhttps://blackhatusa.com/setup.exe | — | |
urlhttp://130.12.180.43/files/7924412375/upOSLDn.exe | — | |
urlhttp://158.94.208.168/files/8514679081/DRTjyu7.exe | — | |
urlhttp://blackhatusa.com/mr.exe | — | |
urlhttp://kuttabilla.top/mr.exe | — | |
urlhttps://75877.mcdir.me/files/2.vbs | — | |
urlhttps://75877.mcdir.me/files/doc1.exe | — | |
urlhttps://milleniumrat.online | — | |
urlhttps://modedapk.net/update1.exe | — | |
urlhttps://www.thesnapchatmodapk.com/update1.exe | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainblackhatusa.com | — | |
domainmodedapk.net | — | |
domainkuttabilla.top | — | |
domainmilleniumrat.online | — | |
domain75877.mcdir.me | — | |
domainwww.thesnapchatmodapk.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash7b6473f036225bc35da89e5049ae55ba | — | |
hashddbc1037925f7d6c07a9ddbe38286a2fcedc4890 | — | |
hashccca11a6d5835999c40a0a5264084b3740633600c157754fad2ef59559e31736 | — | |
hasha1c160243efd54a9bf00655966971aae | — | |
hashcc2c9d90ffba060c9521d40776ffaa907ecec2bb | — | |
hash512adab2c69feaf026adfb12cbd7d2eb4fee746120491e44f476eebddcbb19f2 | — | |
hash66bf111030a2e22db575c0b7b7b677208745eef8b44265bb4259f41f126f1bf8 | — | |
hash7d8b6a64f7b65b281e7b5568929c6f96c62bbae9628162aabe7d8140a86d3de8 | — | |
hash754ba4fb2e083944f84ba50b90ddda87 | — | |
hashf27b08a8347e1ba84a61fbfe58edcb8f84d06642 | — | |
hash5a23ca644cb1f310be1abd5f6c6a3b3e15681ced99b0947a7f3465a79aae5089 | — | |
hash8f8a71352d2f18162f2f74090dc6f0cae6b37029e3244e6522825ade75163055 | — | |
hasha8acc24bb3e6a1a3b66a31ceaefda07d4a0e17415468683458b499f2ba240450 | — | |
hashd55ce447e249ef9045750865fa196c8ca8434c8c484f861b7bdecbceeab7c16e | — | |
hashad0f892b7b99b68491ade4949ef6b575e64d9df5f84a53019b5c1e4eeb4c46a9 | — | |
hash1d699a46339626db299548e32ed3a77eec267840c3de39b49caf38b88aeb150d | — | |
hash066576554f9eff84eaa415a4bd012b2e | — | |
hash07a364ba1b34d0b04bb68872006d9615 | — | |
hash195d1c56f35d7a8d38e2ab0cdc1fa8cd | — | |
hash1ef2f666b543293aaec55d10fbc4bc46 | — | |
hash35af4c61ce04f0c0796baf5831e2ef24 | — | |
hash35dfec976f6fd85f76d011d0075b5926 | — | |
hash3c1032e271dd885e912a79c67f2855e7 | — | |
hash4f32d85224309688c600c21865294717 | — | |
hash52deca7016315faf844f0ba0d754027e | — | |
hash53e78d1fef04a39353a7dbc19f8ac86d | — | |
hash6dc5e2f50900ba1e7a4ee87f950fa409 | — | |
hash87e06d8cec9cf7c2808d17c836089053 | — | |
hash89aa2ce1978f3386f9ee433515e457b1 | — | |
hasha0503abcebf054a006fd4436a73c2dd7 | — | |
hashb82f0480f6403174120f99cdceab83e0 | — | |
hashc704ad8e3fe023e03c4ca07973bd6e78 | — | |
hashd456b165eda38d5d591db9b1bf913463 | — | |
hashf4281c571efa6e0453cf9878a21bb587 | — | |
hash28fbbe5cadb2f4a236acd1977c58bcb7877226e8 | — | |
hash34366f3c17d26856028b472dd8d433913eb2c935 | — | |
hash5a416890fdb135b3c94a70055273d69d48dc6e7f | — | |
hash73a5a94c1222fd333bf3be1322dd09e896159f1a | — | |
hash76330efb09c3355f7547e78cde1c1a0d1f332cb6 | — | |
hash7fad85e9e2c6641498e7c7df4357498b734e3a26 | — | |
hash9d858418c57b513908bba61cb081fbf5914d233a | — | |
hasha684f8c4e1759e4b3cd18d7e3a248d79e4616875 | — | |
hashb1235ce53ef2a09253f7a212369ae2fef1edde4c | — | |
hashb8370381539c085772d3b7503d39573fc7c24ebc | — | |
hashd826b2a24fa3c9b94efd9a33eac7ab2e71abd2c0 | — | |
hashdcff6378b57b6a8ac664254102c656affc62ac49 | — | |
hashe3af48f83557fce9f3dbdc557fa126720ea87983 | — | |
hashe3c0c8761e15442408fc354262c1e206beb4e11f | — | |
hasheb8d7b899ae946face81d88edbacb3e4d2b4ded4 | — | |
hashee9f060b7446336fc9252d2c639ab6e62f324bfe | — | |
hasheff1f644e6006d8a8229d22836f7298930db08ac | — | |
hashfae763674667e007e8287d56b7aa398ac3d66d77 | — | |
hash12b41c07299d2535f7cdc194d97496acd944a9eb5d94b8d24b19291ed9d0830c | — | |
hash19e0070e5009bd5b376b9be997361d0773dcb004200ee8fafe6c14b96cbd93e4 | — | |
hash1c01ab1b59245f24ebdc5d9c414fcf4e2ce31f71f181522efc5a3d27476c8e21 | — | |
hash1d52ded1f3838a1eee849ae20b2fee6c84b183cc98abe7244365b9f34b925eea | — | |
hash2267d05dbd5e30c6dfcdde25731280dd755e689faa684bd21cfbef5281fd3e86 | — | |
hash2d5615acd1b0666995fd124fb72f2713c6609b5368350340288b52fecbdd016d | — | |
hash2d8e5a2763f9a899fda44390d5b8495836c11fb266a61868d52d1f397c5243ee | — | |
hash307964ed02f34bff4e40c5402cc936be07fd9957ef400596a4b3e2cd98c50ec1 | — | |
hash3e17ce0b30b9fd6863b341ae58ee118dc13f2ee7f1c92ac4b81c04d54480d0e0 | — | |
hash4991873515d6dea70d7769cf67ccd8ea69184e5e454a6e6d1e093b6a3c48eb47 | — | |
hash4e035575be8fe350a9e36cf29dbbc8826af2f772672bd08c9e489a243cb90e31 | — | |
hash5562246e38f8935ba8b07350e6aaa44bc22abf37b77f49836fde5999f4b61cf1 | — | |
hash57edeb575862ce8d3bff2eb4d32d9e3fa1ffb7cb8f818e2e7fc6d25a506faea6 | — | |
hash7a370a9262d37de6a24706f92ff0cdded7202281a6ff3bf313721756226ebff9 | — | |
hash8419b1f0acca46d45f4c54c315c8cc4784946e07d547fe55187b928fa6c6b8f5 | — | |
hash848036661c71b80ee41566918faa5eae3bf4f03ae807bb4af42cb483b6c141e2 | — | |
hash85816d89dac648645a9026973772815e956c267232b3d2577a06a43418f19ed3 | — | |
hash88f9e169a85dcf6a1c03bf3ca1b1a262ed32baeca46cb87f0324adfdc098d4a2 | — | |
hash8bef879c6920cdce7c01b8dbb7da24dca23b8822a7aa00dfc72cb32f55879a24 | — | |
hash92710bdb44279dbe8ccff34ba698d1558fa6d271c99ed4960ccbfb6d518d9418 | — | |
hasha4b34b94a905fe330b0a3e4502aa45356e383a8f45ff1d008b785ea0ec14acaf | — | |
hasha911fe0259772906447d7e80a902ea954f3530edd9ea7d0427b6380707a8e681 | — | |
hasha97f15d7bfad02a600eba426c3ef72be34e944a7c8364a975c53866735f7aa4e | — | |
hashaa2ccd18a7a09f66ca5c1bbd927f7fe411bd3874df77b0eaf40738dab7566606 | — | |
hashad74f502cc37e815482df49f118b2f678daf1a3f522daf07a2abeb32c2ed3831 | — | |
hashcc47209d2e4d5a9b2b1d71622b0ad7f73e9c4aa56edd9aaf1e29265650c30f16 | — | |
hashde3842bbb6626912d5b9b01fb775e1843004edb5855d4e627fd74b88bc7fe33b | — | |
hashe4496565d9fd2f9425c10a98d3a8632c12af5fe4259484cb202d7f65532b7df2 | — | |
hashfc41c336b79cbc6559a17d716b84101dbef1adc5357b643a75111af442719611 | — |
Threat ID: 6a3e38cb4853345fc184bae6
Added to database: 06/26/2026, 08:31:07 UTC
Last enriched: 07/31/2026, 12:45:30 UTC
Last updated: 08/09/2026, 11:09:56 UTC
Views: 275
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.