Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Millenium: A RAT Rewritten, A Threat Multiplied

0
Medium
Published: 06/25/2026 (06/25/2026, 18:43:48 UTC)
Source: AlienVault OTX General

Description

Millenium RAT version 4.* is a remote access trojan rewritten from .NET to native C++ that uses the Telegram Bot API for command and control without dedicated servers. It is distributed as Malware-as-a-Service by the developer 'ShinyEnigma' for $50-90 USD. The malware is actively exploited by the threat actor cluster 'Y2K Operators' using social engineering lures such as fraudulent utilities, hacking toolkits, software cracks, and trojanized tools. It enables exfiltration of sensitive browser and system data, screenshot and audio capture, keylogging, and arbitrary executable downloads. Over 62,000 endpoints in more than 160 countries have been compromised, with nearly 40,000 infections in Q1 2026 alone, indicating accelerating spread. No specific affected software versions or patches are identified.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/26/2026, 08:45:55 UTC

Technical Analysis

Millenium RAT v4.* is a remote access trojan that has been significantly re-architected from .NET to native C++. It leverages the Telegram Bot API for command and control, eliminating the need for dedicated C2 infrastructure. Distributed as Malware-as-a-Service by 'ShinyEnigma', it is sold for $50-90 USD. The threat actor cluster 'Y2K Operators' actively deploys this malware using social engineering tactics including fake utilities, hacking toolkits, software cracks, and trojanized cybercrime tools. The RAT facilitates data exfiltration (browser and system data), screen and audio capture, keylogging, and downloading and executing arbitrary files. The malware campaign is widespread, with over 62,000 infected endpoints globally and rapid infection growth in early 2026. There is no indication of a patch or remediation from the vendor or developer, as this is malware rather than a software vulnerability.

Potential Impact

The malware enables attackers to remotely access and control infected systems, exfiltrate sensitive data, capture screenshots and audio, log keystrokes, and execute arbitrary code. This can lead to significant data breaches, espionage, and further compromise of victim networks. The large number of infections and rapid growth indicate a substantial operational impact on affected organizations and individuals worldwide.

Mitigation Recommendations

No official patch or fix exists as this is malware distributed as a service. Mitigation should focus on user education to avoid social engineering lures, deploying updated endpoint protection solutions capable of detecting and blocking Millenium RAT, and network monitoring for suspicious Telegram Bot API traffic. Incident response should include isolating infected hosts and removing the malware. Since the malware uses Telegram for C2, blocking or monitoring Telegram Bot API communications may help reduce exposure.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/millenium-rat-maas/"]
Adversary
Y2K Operators
Pulse Id
6a3d76e592eaea08a66ad337
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip62.60.226.97
ip130.12.180.43
ip158.94.208.168

Url

ValueDescriptionCopy
urlhttps://blackhatusa.com/update.exe
urlhttps://blackhatusa.com/clip.exe
urlhttps://blackhatusa.com/setup.exe
urlhttp://130.12.180.43/files/7924412375/upOSLDn.exe
urlhttp://158.94.208.168/files/8514679081/DRTjyu7.exe
urlhttp://blackhatusa.com/mr.exe
urlhttp://kuttabilla.top/mr.exe
urlhttps://75877.mcdir.me/files/2.vbs
urlhttps://75877.mcdir.me/files/doc1.exe
urlhttps://milleniumrat.online
urlhttps://modedapk.net/update1.exe
urlhttps://www.thesnapchatmodapk.com/update1.exe

Domain

ValueDescriptionCopy
domainblackhatusa.com
domainmodedapk.net
domainkuttabilla.top
domainmilleniumrat.online
domain75877.mcdir.me
domainwww.thesnapchatmodapk.com

Hash

ValueDescriptionCopy
hash7b6473f036225bc35da89e5049ae55ba
hashddbc1037925f7d6c07a9ddbe38286a2fcedc4890
hashccca11a6d5835999c40a0a5264084b3740633600c157754fad2ef59559e31736
hasha1c160243efd54a9bf00655966971aae
hashcc2c9d90ffba060c9521d40776ffaa907ecec2bb
hash512adab2c69feaf026adfb12cbd7d2eb4fee746120491e44f476eebddcbb19f2
hash66bf111030a2e22db575c0b7b7b677208745eef8b44265bb4259f41f126f1bf8
hash7d8b6a64f7b65b281e7b5568929c6f96c62bbae9628162aabe7d8140a86d3de8
hash754ba4fb2e083944f84ba50b90ddda87
hashf27b08a8347e1ba84a61fbfe58edcb8f84d06642
hash5a23ca644cb1f310be1abd5f6c6a3b3e15681ced99b0947a7f3465a79aae5089
hash8f8a71352d2f18162f2f74090dc6f0cae6b37029e3244e6522825ade75163055
hasha8acc24bb3e6a1a3b66a31ceaefda07d4a0e17415468683458b499f2ba240450
hashd55ce447e249ef9045750865fa196c8ca8434c8c484f861b7bdecbceeab7c16e
hashad0f892b7b99b68491ade4949ef6b575e64d9df5f84a53019b5c1e4eeb4c46a9
hash1d699a46339626db299548e32ed3a77eec267840c3de39b49caf38b88aeb150d
hash066576554f9eff84eaa415a4bd012b2e
hash07a364ba1b34d0b04bb68872006d9615
hash195d1c56f35d7a8d38e2ab0cdc1fa8cd
hash1ef2f666b543293aaec55d10fbc4bc46
hash35af4c61ce04f0c0796baf5831e2ef24
hash35dfec976f6fd85f76d011d0075b5926
hash3c1032e271dd885e912a79c67f2855e7
hash4f32d85224309688c600c21865294717
hash52deca7016315faf844f0ba0d754027e
hash53e78d1fef04a39353a7dbc19f8ac86d
hash6dc5e2f50900ba1e7a4ee87f950fa409
hash87e06d8cec9cf7c2808d17c836089053
hash89aa2ce1978f3386f9ee433515e457b1
hasha0503abcebf054a006fd4436a73c2dd7
hashb82f0480f6403174120f99cdceab83e0
hashc704ad8e3fe023e03c4ca07973bd6e78
hashd456b165eda38d5d591db9b1bf913463
hashf4281c571efa6e0453cf9878a21bb587
hash28fbbe5cadb2f4a236acd1977c58bcb7877226e8
hash34366f3c17d26856028b472dd8d433913eb2c935
hash5a416890fdb135b3c94a70055273d69d48dc6e7f
hash73a5a94c1222fd333bf3be1322dd09e896159f1a
hash76330efb09c3355f7547e78cde1c1a0d1f332cb6
hash7fad85e9e2c6641498e7c7df4357498b734e3a26
hash9d858418c57b513908bba61cb081fbf5914d233a
hasha684f8c4e1759e4b3cd18d7e3a248d79e4616875
hashb1235ce53ef2a09253f7a212369ae2fef1edde4c
hashb8370381539c085772d3b7503d39573fc7c24ebc
hashd826b2a24fa3c9b94efd9a33eac7ab2e71abd2c0
hashdcff6378b57b6a8ac664254102c656affc62ac49
hashe3af48f83557fce9f3dbdc557fa126720ea87983
hashe3c0c8761e15442408fc354262c1e206beb4e11f
hasheb8d7b899ae946face81d88edbacb3e4d2b4ded4
hashee9f060b7446336fc9252d2c639ab6e62f324bfe
hasheff1f644e6006d8a8229d22836f7298930db08ac
hashfae763674667e007e8287d56b7aa398ac3d66d77
hash12b41c07299d2535f7cdc194d97496acd944a9eb5d94b8d24b19291ed9d0830c
hash19e0070e5009bd5b376b9be997361d0773dcb004200ee8fafe6c14b96cbd93e4
hash1c01ab1b59245f24ebdc5d9c414fcf4e2ce31f71f181522efc5a3d27476c8e21
hash1d52ded1f3838a1eee849ae20b2fee6c84b183cc98abe7244365b9f34b925eea
hash2267d05dbd5e30c6dfcdde25731280dd755e689faa684bd21cfbef5281fd3e86
hash2d5615acd1b0666995fd124fb72f2713c6609b5368350340288b52fecbdd016d
hash2d8e5a2763f9a899fda44390d5b8495836c11fb266a61868d52d1f397c5243ee
hash307964ed02f34bff4e40c5402cc936be07fd9957ef400596a4b3e2cd98c50ec1
hash3e17ce0b30b9fd6863b341ae58ee118dc13f2ee7f1c92ac4b81c04d54480d0e0
hash4991873515d6dea70d7769cf67ccd8ea69184e5e454a6e6d1e093b6a3c48eb47
hash4e035575be8fe350a9e36cf29dbbc8826af2f772672bd08c9e489a243cb90e31
hash5562246e38f8935ba8b07350e6aaa44bc22abf37b77f49836fde5999f4b61cf1
hash57edeb575862ce8d3bff2eb4d32d9e3fa1ffb7cb8f818e2e7fc6d25a506faea6
hash7a370a9262d37de6a24706f92ff0cdded7202281a6ff3bf313721756226ebff9
hash8419b1f0acca46d45f4c54c315c8cc4784946e07d547fe55187b928fa6c6b8f5
hash848036661c71b80ee41566918faa5eae3bf4f03ae807bb4af42cb483b6c141e2
hash85816d89dac648645a9026973772815e956c267232b3d2577a06a43418f19ed3
hash88f9e169a85dcf6a1c03bf3ca1b1a262ed32baeca46cb87f0324adfdc098d4a2
hash8bef879c6920cdce7c01b8dbb7da24dca23b8822a7aa00dfc72cb32f55879a24
hash92710bdb44279dbe8ccff34ba698d1558fa6d271c99ed4960ccbfb6d518d9418
hasha4b34b94a905fe330b0a3e4502aa45356e383a8f45ff1d008b785ea0ec14acaf
hasha911fe0259772906447d7e80a902ea954f3530edd9ea7d0427b6380707a8e681
hasha97f15d7bfad02a600eba426c3ef72be34e944a7c8364a975c53866735f7aa4e
hashaa2ccd18a7a09f66ca5c1bbd927f7fe411bd3874df77b0eaf40738dab7566606
hashad74f502cc37e815482df49f118b2f678daf1a3f522daf07a2abeb32c2ed3831
hashcc47209d2e4d5a9b2b1d71622b0ad7f73e9c4aa56edd9aaf1e29265650c30f16
hashde3842bbb6626912d5b9b01fb775e1843004edb5855d4e627fd74b88bc7fe33b
hashe4496565d9fd2f9425c10a98d3a8632c12af5fe4259484cb202d7f65532b7df2
hashfc41c336b79cbc6559a17d716b84101dbef1adc5357b643a75111af442719611

Threat ID: 6a3e38cb4853345fc184bae6

Added to database: 06/26/2026, 08:31:07 UTC

Last enriched: 06/26/2026, 08:45:55 UTC

Last updated: 06/26/2026, 11:53:18 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses