logo

njRAT runs MassLogger

ID: f89ebd07-522b-5503-9279-6e2edf3f21a7

STIX ID: report--f89ebd07-522b-5503-9279-6e2edf3f21a7

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-02-02

Date Updated: 2026-04-22

Author: Erik Hjelmvik

...
...

This blog post analyzes njRAT C2 traffic extracted from a public PCAP, demonstrating that the RAT captured full-resolution screenshots, transferred gzip-compressed DLL/EXE payloads (via the "inv" and "rn" commands), and executed a MassLogger credential-stealer (CloudServices.exe). The write-up extracts artifacts and provides IOCs including MD5 hashes, the C2 IP:port, the SMTP server and exfiltration email used by MassLogger.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.