← Back to list

OSINT — ATROPOSIA (Advanced Remote Access Trojan)

We have identified and analyzed the presence and commercial offering of a Remote Access Trojan (RAT) called ATROPOSIA. The product is…

VECERT · 2025-10-19 12:06 · 21 claps · 6.0 min read
#atroposia #osint-investigation #osint #spyware
Open on Medium ↗

OSINT — ATROPOSIA (Advanced Remote Access Trojan)

We have identified and analyzed the presence and commercial offering of a Remote Access Trojan (RAT) called ATROPOSIA. The product is promoted as a multifunctional platform for remote control, exfiltration, and stealth operations (RAT/stealer/hidden RDP), with advanced persistence and evasion capabilities, and a full C2 console. The actor behind the promotion also offers support and sales services through public channels (website and Telegram contact).

Architecture and history

Architecture and history

Key Findings:

Product/Tool: ATROPOSIA — Advanced Remote Access Trojan with multiple modules (RAT, stealer, grabber, HRDP/hidden RDP, vulnerability scanner, DNS hijack, UAC bypass, etc.).

Main Capabilities: Remote control (hidden RDP), remote file execution, credential and wallet exfiltration, clipboard monitoring, process manager, file manager, vulnerability scanning, persistence, UAC bypass, DNS redirection for credential theft.

Architecture: Offers native stubs (no dependencies), separate modules, and unique builds per client (fingerprint evasion, compression to reduce signatures).

Business Model: Sale/lease on a monthly/term subscription basis (plans: $200/month, $500/3 months, $900/6 months). Support via Telegram.

Public Contacts/Resources Detected: Website and server with IOCs (see section 5).

Risk: High — suitable for espionage, credential theft, and persistent control. Immediate risk for environments with weak remote access, endpoints without EDR, or exposed RDP.

In the analyzed documentation/advertisement, a direct reference to Pythia’s Crypter is observed, along with the offer of malware tools (RATs, stealers, backdoors, etc.). The publicly published HTML block contains the description of the crypter:

HTML:

<div class="text-center text-gray-500 text-sm max-w-md font-montserrat px-4">
  Pythia’s Crypter is a professional tool for crypting malicious software, written in C++ and Go with zero external dependencies. <br>

  Its native implementation ensures minimal system interaction, reducing detection risks and maximizing performance.<br>

  The crypter supports any type of malware, including RATs, stealers, HVNC, backdoors, and more, adapting seamlessly to their structure.
</div>

Additionally, it was observed that the service/developer had a public login interface at:

pythiascrypter(.)live

Interpretation: The presence of this technical description of the crypter in the same offer/advertisement and the registration of the login site suggests a commercial/operational relationship between the tool ecosystem (crypter) and the distribution/offering of RATs such as ATROPOSIA. It does not imply definitive attribution; it constitutes evidence of association in the promotional material that must be verified with technical telemetry (artifacts, samples, transactions, logs) to confirm operational links.

ATROPOSIA Russian IP

The scan shows multiple TCP services listening on the IP address 193.233.113.143, with evidence of exposed Windows systems and typical network services (RDP, HTTP, RPC/DCERPC, WSD). This suggests a publicly accessible computer/server responding to multiple Windows protocols. Key ports and observations:

3389 — TCP — RDP (Remote Desktop Protocol)

Partial banner/handshake: \x03\x00\x00\x13\x0e… and Flag label: PROTOCOL_HYBRID_EX.

Target Name: DESKTOP-2NFCDE2

Product Version: 10.0.22000 Ntlm 15 → Windows 11, Version 21H2

System Time: 2025–10–14 04:23:19 +0000 UTC

Implication: RDP is open and responding; the response includes NTLM/host information that may allow OS identification and the computer name.

80 — TCP — HTTP

HTTP/1.1 200 OK, Transfer Encoding: chunked, Content Type: text/html; charset=utf-8

Header Date: Mon, 13 Oct 2025 01:36:16 GMT

Implication: Active web server (possibly dashboard/C2, marketing page, or web interface).

5357 — TCP — HTTP (WSD / Web Services for Devices)

HTTP/1.1 503 Service Unavailable / Server: Microsoft-HTTPAPI/2.0

Port 5357 commonly used by Web Services for Devices (WSDAPI) on Windows — unnecessary exposure to the Internet may leak information and facilitate recognition.

135 — TCP — DCERPC / RPC Endpoint Mapper

Binary response with NTLMSSP and Target_Name: DESKTOP-TCRDU4C

Product_Version: 10.0.19041 NTLM 15 → Windows 10, Version 2004 / Windows Server 2004

DCERPC dump shows reference to schedsvc.dll and pipes as \PIPE\atsvc (related to Task Scheduler / service).

Implication: RPC services exposing NetBIOS/SMB/pipe information and hostnames. It also indicates the presence of at least one other hostname (DESKTOP-TCRDU4C) — this could be:

the same host with multiple names/aliases,

multiple hosts with the same IP behind a NAT/virtualized host, or

liveness service artifacts/cached responses.

Threat Actor Profile:

The nodes represent actors, services or identifiers, and the lines indicate direct relationships (use, support, or commercial link).

The nodes represent actors, services or identifiers, and the lines indicate direct relationships (use, support, or commercial link).

The payment channels of this criminal clan are operated through BTC cryptocurrency. The “nowpayments” payment system allows the change of wallet address generated for each plan and in each new payment generation.

Its public reference is notable and even in forums such as “hackforums” and some YouTube addresses

Its public reference is notable and even in forums such as “hackforums” and some YouTube addresses

Multi-channels generated to spread an illegal service but which refer to the same profile or Telegram channel-

Multi-channels generated to spread an illegal service but which refer to the same profile or Telegram channel-

Landing Page

Landing Page

According to Telegram records, the actor has been around since 2024 and has been inspired by the use of names like “Melatonin.”

IOCs:

IOCs (obfuscated/hidden)

Domains / URLs

a*****sia.lol (infrastructure/panel domain)

pythia*****.live (crypter login site)

IP Addresses

193.233.113.xxx (associated public IP: RDP/HTTP/SMB/RPC detected)

Detected Ports
(indicate services observed on the obfuscated IP)

3389/TCP — RDP

80/TCP — HTTP

135/TCP — DCERPC/RPC

445/TCP — SMB

5357/TCP — WSD/HTTP

Aliases / Hostnames

DESKTOP-2NFC**** (hostname observed in RDP banner)

DESKTOP-TCRD**** (hostname observed in RPC/SMB banner)

Cryptocurrency Address(es) (payments)

37JStk******rch3T7 (Partial BTC address — license payments)

Channels / Contact

@Mela*****_Support (support/sales channel — Telegram)

Related tools / references

pythia's crypter — referenced in the documentation (supports RAT/stealer/HVNC crypting). (Name intact, site obfuscated above.)

The consolidated analysis of evidence indicates that ATROPOSIA is a remote access and information theft (RAT/Stealer) platform marketed under a Malware-as-a-Service (MaaS) model. Its architecture combines advanced remote control functionalities (hidden RDP, process injection, persistence, and data exfiltration) with credential theft modules and evasion capabilities.

During the investigation, a technical and financial ecosystem clearly structured around the alias “Melatonin” was identified, responsible for promoting, supporting, and collecting licenses for the malware through cryptocurrency. The observed infrastructure, including domains, IP addresses, and active services (HTTP, RDP, SMB, and RPC), shows traces consistent with compromised Windows environments or those repurposed as command and control servers.

Furthermore, the historical connection between ATROPOSIA and the Pythia’s Crypter crypter was confirmed, a tool used to obfuscate malicious binaries and reduce their detection by antivirus solutions, reinforcing the professionalized nature of this ecosystem.

The body of technical evidence, network metadata, and payment relationships demonstrates that ATROPOSIA is part of an active organized cybercrime infrastructure, with modular components, commercial technical support, and monetization mechanisms through cryptocurrencies and external payment gateways.

LEGAL & ETHICAL DISCLAIMER

This report is based exclusively on publicly available information obtained through Open-Source Intelligence (OSINT). No intrusion, hacking, unauthorized system access, interception, credential harvesting, exploitation, or acquisition of private or confidential data has been performed.

All observations, indicators, infrastructure references, metadata, signals, or correlations presented in this report are derived from publicly accessible sources and must be treated as technical intelligence, not as definitive or judicial attribution.

The presence of domains, IP addresses, log patterns, underground references, or leaked information does not constitute a formal accusation or legal determination of responsibility. Attribution, motivation, and actor identity may require additional validation by competent authorities, legal entities, or digital forensics.

The content contained in this report may include potential false positives, infrastructure that later changes ownership, expired datasets, or previously exposed material. Intelligence derived from OSINT should always be corroborated and verified before any operational, legal, investigative, financial, or organizational action is taken.

The analysis provided here is strictly for educational, academic, security research, cyber risk evaluation, and threat-intelligence purposes. It must not be used for harassment, personal retaliation, unauthorized surveillance, doxing, stalking, profiling of individuals, or any unethical or illegal activity.

Vecert does not store, distribute, commercialize, or trade stolen, private, or illicit data. All data indexed, referenced, or analyzed is already publicly available at the time of research.

Any interpretation, operational decision, investigative direction, mitigation action, or use of the intelligence included in this report is performed entirely at the reader’s own responsibility. This publication does not replace formal legal advice, law-enforcement investigation, digital forensics, or compliance assessments.

메타데이터
post_id
4077c080f181
slug
osint-atroposia-advanced-remote-access-trojan-4077c080f181
url
https://medium.com/@vecert/osint-atroposia-advanced-remote-access-trojan-4077c080f181
canonical_url
https://medium.com/@vecert/osint-atroposia-advanced-remote-access-trojan-4077c080f181
author_url
https://medium.com/@vecert
status
ok
fetched_at
2026-06-12 07:40:50