Description

The Password Recovery feature in malware is engineered to retrieve stored passwords from a variety of sources on the compromised system. Unlike brute-force or dictionary attacks that attempt to guess passwords, this feature targets saved credentials in browsers, email clients, and even software applications. The malware may scan cookies, encrypted password vaults, and even specific registry entries to recover these hidden gems of authentication data. Once harvested, the credentials can be used for privilege escalation, unauthorized access to sensitive accounts, or even financial fraud. The Password Recovery feature thus serves a critical role in the malware's arsenal, enabling the attacker to extend their reach within the compromised system and across linked networks or accounts, all while bypassing traditional methods of authentication.


Categories Lateral Movements, Credentials, Privilege Escalation
Dangerousness High

Associated with Releases

Version Origins Authors Languages Release Date
ProRat 1.9 logoProRat 1.9 Turkey πŸ‡ΉπŸ‡· HighLander , ATmaCA Borland C++ Mar, 2005
Y3K rat 2k5 RC 1.0 logoY3K rat 2k5 RC 1.0 Germany πŸ‡©πŸ‡ͺ SHA Delphi Jun, 2005
DARKMOON 4.11 / 4.11 Private Edition logoDARKMOON 4.11 / 4.11 Private Edition Spain πŸ‡ͺπŸ‡Έ shukisnike Delphi Jun, 2005
Turkojan 3.0 logoTurkojan 3.0 Turkey πŸ‡ΉπŸ‡· Fungus Delphi Sep, 2006
Bifrost 1.2.1 logoBifrost 1.2.1 Sweden πŸ‡ΈπŸ‡ͺ ksv C++ Jan, 2007
Bandook 1.35 logoBandook 1.35 Lebanon πŸ‡±πŸ‡§ PrinceAli Delphi, C++ Apr, 2007
Poison Ivy 2.3.0 logoPoison Ivy 2.3.0 Sweden πŸ‡ΈπŸ‡ͺ Shapeless Delphi, MASM Jun, 2007
Hav-Rat 1.3.2 logoHav-Rat 1.3.2 Sweden πŸ‡ΈπŸ‡ͺ Havalito Delphi Jul, 2007
sharK 2.4.0 Fwb+ logosharK 2.4.0 Fwb+ Germany πŸ‡©πŸ‡ͺ sNiper109 , rockZ Visual Basic 6 (VB6) Aug, 2007
Poison Ivy 2.3.2 logoPoison Ivy 2.3.2 Sweden πŸ‡ΈπŸ‡ͺ Shapeless Delphi, MASM Jan, 2008
Turkojan 4 logoTurkojan 4 Turkey πŸ‡ΉπŸ‡· FΒ΅NG¡§ Delphi Feb, 2008
Turkojan 4.0 logoTurkojan 4.0 Turkey πŸ‡ΉπŸ‡· Fungus Delphi Mar, 2008
Lost Door 3.0 Stable logoLost Door 3.0 Stable Tunisia πŸ‡ΉπŸ‡³ OussamiO Visual Basic 6 (VB6) Mar, 2009
SynRAT 4.0.1 logoSynRAT 4.0.1 France πŸ‡«πŸ‡· DarkCoderSc Delphi May, 2009
Cerberus 1.0 Beta logoCerberus 1.0 Beta United States πŸ‡ΊπŸ‡Έ, United Kingdom πŸ‡¬πŸ‡§ Protocol , Steve10120 , 2sly , Sam Delphi Aug, 2009
Cerberus 1.01 Beta logoCerberus 1.01 Beta United States πŸ‡ΊπŸ‡Έ, United Kingdom πŸ‡¬πŸ‡§ Protocol , Steve10120 , 2sly , Sam Delphi Aug, 2009
Cerberus 1.02 Beta logoCerberus 1.02 Beta United States πŸ‡ΊπŸ‡Έ, United Kingdom πŸ‡¬πŸ‡§ Protocol , Steve10120 , 2sly , Sam Delphi Aug, 2009
SynRAT 4.3.1-A-1 logoSynRAT 4.3.1-A-1 France πŸ‡«πŸ‡· DarkCoderSc Assembly, Delphi Aug, 2009
Apocalypse RAT 1.4 logoApocalypse RAT 1.4 Turkey πŸ‡ΉπŸ‡· ap0calypse Delphi Aug, 2009
Cerberus 1.03.4 logoCerberus 1.03.4 United States πŸ‡ΊπŸ‡Έ, United Kingdom πŸ‡¬πŸ‡§ Protocol , Steve10120 , 2sly , Sam Delphi Sep, 2009
Spy-Net 2.6 logoSpy-Net 2.6 Brazil πŸ‡§πŸ‡· Raphael Delphi Oct, 2009
DarkComet RAT 1.3 logoDarkComet RAT 1.3 France πŸ‡«πŸ‡· DarkCoderSc Nov, 2009
Cerberus 1.03.5 Beta logoCerberus 1.03.5 Beta United States πŸ‡ΊπŸ‡Έ, United Kingdom πŸ‡¬πŸ‡§ Protocol , Steve10120 , 2sly , Sam Delphi Dec, 2009
DarkComet RAT 2.0 RC4 logoDarkComet RAT 2.0 RC4 France πŸ‡«πŸ‡· DarkCoderSc Delphi Mar, 2010
CyberGate 1.04.8 logoCyberGate 1.04.8 United States πŸ‡ΊπŸ‡Έ johnyk Delphi Apr, 2010
Lost Door 4.3.1 logoLost Door 4.3.1 Tunisia πŸ‡ΉπŸ‡³ OussamiO Visual Basic 6 (VB6) Apr, 2010
DarkComet RAT 2.0 RC7 logoDarkComet RAT 2.0 RC7 France πŸ‡«πŸ‡· DarkCoderSc Assembly, Delphi Jun, 2010
Schwarze Sonne 1.0 logoSchwarze Sonne 1.0 Unknown πŸ΄β€β˜ οΈ, Germany πŸ‡©πŸ‡ͺ, Turkey πŸ‡ΉπŸ‡· ap0calypse , Slayer616 , Counterstrikewi Delphi Jun, 2010
Lost Door 5.1 logoLost Door 5.1 Tunisia πŸ‡ΉπŸ‡³ OussamiO Visual Basic 6 (VB6) Oct, 2010
Xtreme RAT 2.9 logoXtreme RAT 2.9 Brazil πŸ‡§πŸ‡· Raphael Delphi Jul, 2011
DarkComet RAT 5.3 logoDarkComet RAT 5.3 France πŸ‡«πŸ‡· DarkCoderSc Assembly, Delphi Jun, 2012
DarkComet RAT 5.3.1 logoDarkComet RAT 5.3.1 France πŸ‡«πŸ‡· DarkCoderSc Assembly, Delphi Jun, 2012
NjRat 0.7d logoNjRat 0.7d Kuwait πŸ‡°πŸ‡Ό njq8 VB .net Dec, 2013
Quasar 1.0 logoQuasar 1.0 Unknown πŸ΄β€β˜ οΈ MaxXor C# Aug, 2015