Netskope Threat Labs

StrRat

ATP Sandbox Adv. HeuristicsNetskope IPS

StrRat is a Java based remote access trojan that uses plugins extensively to provide full remote access, credential stealing, and keylogging. It targets browser and email client credentials from Firefox, Internet Explorer, Chrome, Foxmail, Outlook, and Thunderbird, and from version 1.2 onward it was infamous for ransomware-like behavior that appended the .crimson extension to files.

First seen
June 2022
Last seen
October 2026
Strrat
Alert Name
ByteCode-JAVA.Backdoor.Strrat
ByteCode-JAVA.Trojan.Strrat
ByteCode-JAVA.Trojan.StrRat
Document-Excel.Trojan.Strrat
Package.Trojan.Strrat
Win32.Exploit.Strrat