Netskope Threat Labs

WmRAT

ATP Sandbox Adv. HeuristicsAV

WmRAT is a C++ remote access trojan that uses socket based communications and standard RAT functionality. It gathers host information, uploads and downloads files, takes screenshots, collects geolocation data, enumerates directories, and runs arbitrary commands through cmd or PowerShell, and it spawns junk threads that can mislead researchers investigating samples.

First seen
January 2025
Last seen
September 2026
Alert Name
Gen:Variant.WmRAT.1
Win32.Backdoor.WmRAT
Win32.Trojan.WmRAT