Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Millenium: A RAT Rewritten, A Threat Multiplied

a911fe0259772906447d7e80a902ea954f3530edd9ea7d0427b6380707a8e681

TLP:CLEAR
Active

SHA-256 Hash

Description

Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone significant architectural changes from .NET to native C++, while continuing to leverage Telegram Bot API for command and control without requiring dedicated server infrastructure. The malware is distributed as Malware-as-a-Service by developer 'ShinyEnigma' for $50-90 USD. Active exploitation campaigns are conducted by threat actor cluster 'Y2K Operators' using social engineering tactics including fraudulent utilities, hacking toolkits, software cracks, gaming lures, and trojanized cybercrime tools. The trojan enables exfiltration of sensitive browser and system data, screenshot and audio capture, keylogging, and arbitrary executable downloads. Over 62,000 compromised endpoints across more than 160 countries have been identified, with 39,730 infections occurring in Q1 2026 alone, demonstrating accelerating infection rates.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Millenium: A RAT Rewritten, A Threat Multiplied
Pattern Type
STIX
Confidence
75%
Valid From
Jul 25, 2026 20:01
Total Sightings
0
Added
Jul 25, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of a911fe0259772906447d7e80a902ea954f3530edd9ea7d0427b6380707a8e681

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.