logo

njRAT Pushes Lime Ransomware & Bitcoin Stealer

ID: c54cedf1-33f0-5af6-8b26-1bf7d7188508

STIX ID: report--c54cedf1-33f0-5af6-8b26-1bf7d7188508

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

njRAT Lime Edition is a .NET-based remote access trojan variant observed in the wild that combines remote control, credential and cryptocurrency wallet theft, keylogging, USB worm propagation, bot-killing, DDoS capabilities, and an integrated AES-256 ransomware component that encrypts files with a .lime extension; the report includes configuration excerpts, C2 domains (duckdns), MD5 hashes, and vendor detection names.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.