Executive Summary
CARROTBAT is a Windows dropper that delivers the SYSCON RAT via custom installers, using shared infrastructure with KONNI. It gains persistence through registry keys and communicates over HTTPS to exfiltrate data and receive commands. Continuous vigilance against its download vectors and command servers remains critical for affected organizations.
Enhanced Description
CARROTBAT is a sophisticated, Windows‑based dropper that has been observed in the wild since at least 2017.^1 The tool’s primary function is to deliver a secondary payload—most notably the SYSCON backdoor—which establishes persistence and facilitates remote command and control operations. CARROTBAT leverages custom installers and stealthy download mechanisms, allowing attackers to sidestep antivirus detection by employing obfuscated binaries and encrypted network traffic. Operational analyses reveal that CARROTBAT shares infrastructure with the well‑known KONNI ransomware group, suggesting a common threat actor or shared supply chain for command‑and‑control servers. The dropper typically initiates through malicious attachments or drive‑by downloads, gains foothold via user execution of the installer, and then writes its payload to privileged system directories before adding self‑executing entries in the Windows registry (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run). Once deployed, SYSCON opens a persistent channel back to the attacker’s command server using HTTP/S, enabling data exfiltration, lateral movement, and credential theft. The long deployment window indicates an ongoing threat actor campaign that regularly updates both infrastructure and payload variants. Despite limited public attribution, security researchers have documented several distinct CARROTBAT infections across multiple industries, underscoring the need for continuous monitoring of known domain patterns and file signatures associated with this family.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core capabilities—dropper function, deployment of SYSCON, and persistence tactics—is moderate due to corroborated evidence from Unit 42 reports. However, specific technical details such as exact encryption methods, complete command set, and full threat actor attribution remain uncertain, creating gaps that warrant further investigation.
CARROTBAT is a customized dropper that has been in use since at least 2017. CARROTBAT has been used to install SYSCON and has infrastructure overlap with KONNI.(Citation: Unit 42 CARROTBAT November 2018)(Citation: Unit 42 CARROTBAT January 2020)