Netskope Threat Labs

njRAT

ATP Sandbox Adv. HeuristicsAVNetskope IPS

njRAT (a.k.a. Bladabindi) is a remote access trojan with extensive capabilities, including keystroke logging, credential theft from browsers, camera access, and file management. Its point and click builder lowered the barrier to running spyware, and operators ranging from adolescents to state sponsored crews have used it for years. Detections under this name indicate an active implant that should trigger a credential reset and full cleanup.

First seen
January 2022
Last seen
October 2026
BandookBladabindiBladabindiDldrNjRAT

31 techniques across 10 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0006 Credential Access

  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1010Application Window Discovery
  • T1012Query Registry
  • T1018Remote System Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1120Peripheral Device Discovery

TA0008 Lateral Movement

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

Alert Name
ByteCode-MSIL.Backdoor.njRAT
ByteCode-MSIL.Backdoor.NjRAT
ByteCode-MSIL.Downloader.Bladabindi
ByteCode-MSIL.Hacktool.Bladabindi
ByteCode-MSIL.Trojan.Bladabindi
ByteCode-MSIL.Trojan.NjRAT
ByteCode-MSIL.Worm.Bladabindi
DeepScan:Generic.MSIL.Bladabindi.736DEF22
DeepScan:Generic.MSIL.Bladabindi.981A38A5
Dropped:Generic.MSIL.Bladabindi.1131DD49