Netskope Threat Labs

LimeRAT

ATP Sandbox Adv. HeuristicsAV

LimeRAT is a .NET based remote access trojan that gives cyberattackers extensive control over infected systems, including remote shell, keylogging, and cryptocurrency wallet theft. Its open source builder and plugin architecture made it popular with low skilled operators, and its simple control panel lowered the barrier to running campaigns. It spreads through phishing, cracked software, and loader chains, and its features center on data theft rather than stealth.

First seen
May 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Backdoor.LimeRAT
Generic.MSIL.LimeRAT.14123607
Generic.MSIL.LimeRAT.2C615EA8
Generic.MSIL.LimeRAT.339FD01A
Generic.MSIL.LimeRAT.433BCB8A
Generic.MSIL.LimeRAT.4DA13543
Generic.MSIL.LimeRAT.4F436709
Generic.MSIL.LimeRAT.6075D482
Generic.MSIL.LimeRAT.638DCA07
Generic.MSIL.LimeRAT.757A8C75