NJRAT
BLADABINDI
.NET RAT
LIME EDITION
Threat IntelligenceMalwareDecember 18, 202515 min read

NjRAT: The Immortal .NET RAT Still Thriving After 13 Years

How a leaked-source remote access trojan from 2012 became one of the most persistent threats in cybercrime — with a GUI builder that turns script kiddies into capable attackers and nation-state groups into stealthy operators.

Scroll

NjRAT (also known as Bladabindi, tracked as MITRE ATT&CK S0385) is a .NET-based remote access trojan that has been active since November 2012. After its source code was leaked in 2013, it became one of the most widely deployed RATs in history — used by everyone from script kiddies to nation-state groups including Group5 (Iran) and SideCopy (Pakistan).

Overview & History

NjRAT was originally developed by a Kuwaiti developer using the handle "njq8" and released on Arabic-language hacking forums. The malware's source code leak in 2013 transformed it from a niche tool into a global phenomenon, spawning dozens of variants and forks that continue to proliferate in 2026.

Enduring Threat

NjRAT has been continuously active for 13+ years, consistently ranking among the top 10 most-detected RATs globally. Its longevity stems from the combination of source code availability, GUI-based builder simplicity, and continuous community-driven development.

Builder & Capabilities

NjRAT's GUI builder is the key to its proliferation. It allows operators with minimal technical skill to generate fully functional RAT payloads:

Core RAT Features

Destructive Capabilities

Technical Analysis

Execution & Persistence

C2 Protocol

USB Worm Module

Self-Propagation

NjRAT includes a USB worm module that copies itself to removable drives and creates autorun entries, enabling offline propagation across air-gapped networks.

Variants & Forks

VariantKey Features
NjRAT (Original)Core RAT functionality; GUI builder; source leaked 2013
Lime EditionAdded DDoS, Bitcoin mining, USB spread, ransomware module
NjRAT 0.7d GoldenEnhanced evasion; persistence improvements; community fork
NjRAT Green EditionImproved stability; additional stealer modules
njRAT Danger EditionAdvanced features; botnet management improvements
Custom APT variantsHeavily modified versions used by state-sponsored groups

Threat Actor Usage

Threat ActorRegionUsage Context
Group5IranEspionage against Syrian opposition and diaspora communities
SideCopyPakistanOperations targeting Indian military and government entities
Earth BogleMiddle EastGeopolitically motivated campaigns across MENA region
BlindEagle (APT-C-36)Latin AmericaFinancial espionage targeting Colombian entities
Gorgon GroupPakistanDual espionage and cybercrime operations
Script kiddies (global)WorldwideLow-sophistication attacks, gaming community targeting

MITRE ATT&CK Mapping

TacticTechniqueUsage
PersistenceT1547.001 Registry Run KeysAutostart persistence via HKCU Run key
Defense EvasionT1036 MasqueradingMimics legitimate system process names
Credential AccessT1056.001 KeyloggingRecords all keystrokes
Credential AccessT1555.003 Browser CredentialsExtracts saved browser passwords
CollectionT1125 Video CaptureWebcam streaming and capture
CollectionT1123 Audio CaptureMicrophone recording
CollectionT1113 Screen CaptureDesktop screenshots
CollectionT1005 Data from Local SystemFile browsing and exfiltration
Lateral MovementT1091 Replication via MediaUSB worm propagation
C2T1095 Non-Application LayerCustom TCP protocol on port 5552

Microsoft Dev Tunnels Abuse (2025)

Infrastructure Evasion

In early 2025, NjRAT operators began abusing Microsoft Dev Tunnels — a legitimate developer service for exposing local ports to the internet — as C2 infrastructure. This technique routes all C2 traffic through Microsoft's trusted infrastructure, bypassing domain reputation checks.

Detection & Defense

Protect Against Remote Access Trojans

Mjolnir Security provides comprehensive RAT detection, response, and prevention services.

RAT DetectionEndpoint SecurityThreat HuntingIncident ResponseMDR ServicesUSB Security
  • RAT Detection & Removal Identify and remediate NjRAT infections including all variants, persistence mechanisms, and lateral movement artifacts across your environment.
  • Infrastructure Abuse Detection Monitor for abuse of legitimate services (Dev Tunnels, ngrok, Cloudflare Tunnels) as C2 channels that bypass traditional security controls.
  • 24/7 Incident Response Rapid containment and forensic investigation when RAT activity is detected. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: December 18, 2025