Executive Summary
BabylonRAT is a functional Remote Access Trojan that resurfaced in 2023–2024 campaigns, notably targeting political figures and public institutions in Malaysia. The malware masquerades as legitimate software, such as Mozilla Firefox, to infiltrate Windows systems. Once active, it establishes persistence, conducts extensive reconnaissance, and awaits commands from a central Command and Control (C2) server.
Technically, the malware utilizes dynamic API resolution and XOR-based obfuscation to evade static detection. It employs a wide array of capabilities including system information discovery, browser credential harvesting (Chrome/Firefox), keylogging, and remote file management. Its modular command structure also supports more aggressive actions like launching DDoS attacks and modifying system HOSTS files to redirect traffic.
The threat is significant for organizations due to its comprehensive data exfiltration capabilities and ability to act as a persistent backdoor for further payload delivery. Its use of open-source code and masquerading techniques underscores the need for robust endpoint monitoring and behavioral analysis to detect non-standard file behaviors in directories like ProgramData.
