Analysis of Lightlife RAT HTA Dropper
Score: 9/10

Analysis of Lightlife RAT HTA Dropper

A multi-stage HTA-based loader uses VBScript and PowerShell to deploy the Lightlife RAT, targeting crypto wallets and establishing persistence via Russian infrastructure.

Executive Summary

A sophisticated multi-stage infection chain has been identified using malicious HTML Application (HTA) files disguised as VLC media presentations. The attack begins with an HTA file execution that utilizes VBScript and JavaScript to drop a primary loader, which subsequently fetches and executes the 'Lightlife' Remote Access Trojan (RAT). The malware is primarily designed for information theft, specifically targeting cryptocurrency wallet browser extensions and system metadata.

The technical workflow leverages living-off-the-land binaries (LOLBins) including mshta.exe, wmic.exe, and wscript.exe to evade traditional detection. Once executed, the PowerShell-based payload (lightlife.ps1) establishes persistence through registry modifications and utilizes the Telegram Bot API for exfiltration notifications. The infrastructure is hosted on a Russian C2 server (91.196.32[.]232), which serves decoy media files to distract users while the infection proceeds in the background.

This threat represents a significant risk to organizations and individuals managing digital assets. The use of fileless PowerShell execution, AMSI bypasses, and multi-stage delivery through authenticated tokens indicates a high level of operational maturity. Defenders should prioritize monitoring for anomalous HTA execution and suspicious PowerShell commands involving encoded payloads and external network requests.

Key Details

Threat Name

Lightlife RAT

Affects

—

Adversary

—

Malware/Tools

lightlife.ps1, DarkWatchman, Pay2Key, Vile, Ironchain

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance8
Enterprise Relevance8
Clarity & Structure8
Technical Depth9

Sources