SYMBOLCOMMON_NAMEaka. SYNONYMS
win.astarion_rat (Back to overview)

AstarionRAT

aka: MIMICRAT
VTCollection    

According to Huntress, AstarionRAT is a full-featured RAT with 24 commands, including credential theft, SOCKS5 proxy, port scanning, reflective code loading, and shell execution, with RSA-encrypted C2 communication disguised as application telemetry.

References
2026-02-19 ⋅ Elastic ⋅ Elastic Security Labs, Salim Bitam
MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites
AstarionRAT
2026-02-16 ⋅ Huntress Labs ⋅ Anna Pham, Michael Tigges
ClickFix Won't Die. Neither Will Matanbuchus. A New RAT and a Hands-on-Keyboard Intrusion
AstarionRAT Matanbuchus
Yara Rules
[TLP:WHITE] win_astarion_rat_auto (20260917 | Detects win.astarion_rat.)
rule win_astarion_rat_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.astarion_rat."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.astarion_rat"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 488d542430 0fb605???????? 4533c9 4533c0 f20f11442430 }
            // n = 5, score = 100
            //   488d542430           | inc                 esp
            //   0fb605????????       |                     
            //   4533c9               | mov                 esi, edi
            //   4533c0               | inc                 ecx
            //   f20f11442430         | lea                 eax, [eax + ebx]

        $sequence_1 = { 48894610 e8???????? 488b5e10 eb07 488bf3 488b5b10 4885db }
            // n = 7, score = 100
            //   48894610             | mov                 ecx, ebp
            //   e8????????           |                     
            //   488b5e10             | pop                 ebx
            //   eb07                 | ret                 
            //   488bf3               | dec                 eax
            //   488b5b10             | lea                 eax, [0x172c9]
            //   4885db               | dec                 eax

        $sequence_2 = { 48898424a0040000 8b09 48c744243000000000 e8???????? 8bd8 e8???????? }
            // n = 6, score = 100
            //   48898424a0040000     | test                ebx, ebx
            //   8b09                 | jmp                 0x1145
            //   48c744243000000000     | dec    eax
            //   e8????????           |                     
            //   8bd8                 | mov                 edx, ebx
            //   e8????????           |                     

        $sequence_3 = { 742f 4885c0 7521 4c8d0d2f120100 33c9 4c8d0522120100 488d1523120100 }
            // n = 7, score = 100
            //   742f                 | movups              xmm0, xmmword ptr [ecx]
            //   4885c0               | dec                 ecx
            //   7521                 | mov                 ebx, eax
            //   4c8d0d2f120100       | mov                 dword ptr [esp + 0x58], 0x208
            //   33c9                 | dec                 esp
            //   4c8d0522120100       | mov                 edi, edx
            //   488d1523120100       | mov                 dword ptr [esp + 0x5c], 0x660e

        $sequence_4 = { 85c0 0f8497000000 e8???????? 85c0 757a 8b4c2460 ba01000000 }
            // n = 7, score = 100
            //   85c0                 | lea                 edx, [ebp + 0x5c0]
            //   0f8497000000         | inc                 ecx
            //   e8????????           |                     
            //   85c0                 | mov                 eax, 0x8000
            //   757a                 | dec                 ecx
            //   8b4c2460             | mov                 ecx, esp
            //   ba01000000           | test                eax, eax

        $sequence_5 = { eb09 b005 eb05 0fb6442435 8074243410 3410 }
            // n = 6, score = 100
            //   eb09                 | jmp                 0x12fa
            //   b005                 | dec                 eax
            //   eb05                 | mov                 ecx, ebx
            //   0fb6442435           | dec                 eax
            //   8074243410           | mov                 ecx, dword ptr [esp + 0x60]
            //   3410                 | dec                 eax

        $sequence_6 = { c605????????01 b001 4883c428 c3 4883ec28 e8???????? 488d15bca00100 }
            // n = 7, score = 100
            //   c605????????01       |                     
            //   b001                 | inc                 ecx
            //   4883c428             | inc                 esp
            //   c3                   | cmp                 eax, dword ptr [ebx]
            //   4883ec28             | jb                  0x345
            //   e8????????           |                     
            //   488d15bca00100       | inc                 ecx

        $sequence_7 = { 4889742440 33f6 4c89742438 4c897c2430 0f1f4000 6666660f1f840000000000 8b0d???????? }
            // n = 7, score = 100
            //   4889742440           | arpl                word ptr [ebx + 8], ax
            //   33f6                 | dec                 ecx
            //   4c89742438           | add                 eax, eax
            //   4c897c2430           | cmp                 ax, 5
            //   0f1f4000             | ja                  0x2045
            //   6666660f1f840000000000     | dec    eax
            //   8b0d????????         |                     

        $sequence_8 = { 4157 488dac2480f8ffff 4881ec80080000 488b05???????? 4833c4 48898570070000 4c89442468 }
            // n = 7, score = 100
            //   4157                 | cmp                 eax, ebp
            //   488dac2480f8ffff     | ja                  0x365
            //   4881ec80080000       | inc                 ecx
            //   488b05????????       |                     
            //   4833c4               | sub                 edx, eax
            //   48898570070000       | inc                 ecx
            //   4c89442468           | mov                 dword ptr [ecx + ecx], edx

        $sequence_9 = { 0f298520010000 0f2805???????? 0f298d00010000 0f280d???????? 88851a010000 0fb705???????? }
            // n = 6, score = 100
            //   0f298520010000       | mov                 ecx, eax
            //   0f2805????????       |                     
            //   0f298d00010000       | dec                 ebp
            //   0f280d????????       |                     
            //   88851a010000         | mov                 eax, ebp
            //   0fb705????????       |                     

    condition:
        7 of them and filesize < 462848
}
Download all Yara Rules