Netskope Threat Labs

WarzoneRAT

ATP Sandbox Adv. HeuristicsAVNetskope IPS

WarzoneRAT (a.k.a. AveMaria) is a malware as a service remote access tool written in C++ that has been publicly available for purchase since at least late 2018.

First seen
May 2022
Last seen
October 2026
AveMariaWarzoneWarzoneRatWarzonerat

30 techniques across 12 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0004 Privilege Escalation

  • T1546Event Triggered Execution
  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0006 Credential Access

  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0008 Lateral Movement

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

Alert Name
ByteCode-MSIL.Backdoor.AveMaria
ByteCode-MSIL.Backdoor.Warzone
ByteCode-MSIL.Backdoor.WarzoneRAT
ByteCode-MSIL.Spyware.AveMaria
ByteCode-MSIL.Trojan.AveMaria
ByteCode-MSIL.Trojan.WarzoneRat
ByteCode-MSIL.Trojan.WarzoneRAT
Gen:Variant.AveMaria.4
Win32.Backdoor.AveMaria
Win32.Backdoor.Warzone