Millenium RAT Capability Matrix
Reported capabilities organized by category — what the malware can do on a compromised Windows endpoint.
What can Millenium RAT do? Millenium RAT can steal browser credentials, cookies, history, payment-card data, Discord tokens, Telegram data and cryptocurrency wallets; perform keylogging, screenshot, webcam and audio capture; reconnaissance of system hardware and security products; remote control including shell execution and file management; and disruptive functions including file encryption and forced shutdown. Capabilities are summarized by function and security impact, not as an operator manual.
Information Stealing
11 items- ▸Browser credentials
- ▸Browser cookies
- ▸Browsing history
- ▸Stored browser information
- ▸Downloaded-file metadata
- ▸Saved payment-card information (where available)
- ▸Desktop / user files
- ▸System information
- ▸Discord session / token information
- ▸Telegram-related information
- ▸Cryptocurrency / browser-extension wallet data (newer versions)
Surveillance
5 items- ▸Keylogging
- ▸Screenshot capture
- ▸Webcam capture
- ▸Microphone / audio capture
- ▸Active-window information
System Reconnaissance
9 items- ▸Username & administrator status
- ▸Operating-system information
- ▸CPU / GPU
- ▸Installed RAM
- ▸Hardware identifier
- ▸System architecture
- ▸Installed programs
- ▸Antivirus / security-product information
- ▸Running processes
Remote Access / Control
9 items- ▸Remote process interaction
- ▸File management
- ▸Opening URLs
- ▸Executing files
- ▸Downloading additional payloads
- ▸Remote shell / command execution
- ▸PowerShell-related execution capability
- ▸System restart / shutdown / logoff
- ▸UI manipulation
Collection & Exfiltration
4 items- ▸File collection
- ▸Archiving of collected data
- ▸Exfiltration via Telegram infrastructure
- ▸Larger-file transfers via third-party file-transfer infrastructure
Impact / Disruptive Functions
6 items- ▸File encryption / decryption functionality
- ▸Deletion / manipulation of files
- ▸Forced shutdown / restart
- ▸System disruption
- ▸Blue Screen (BSOD) triggering
- ▸Display manipulation
Is Millenium RAT ransomware?
No — not by default. Researchers documented file encryption/decryption functionality, but the presence of encryption does not mean every Millenium RAT infection becomes a ransomware incident. Millenium RAT is primarily a remote-access trojan and infostealer. The encryption capability is one of several impact functions, not the malware's core purpose.
- ▸Information stealing spans browsers, Discord, Telegram, and crypto wallets.
- ▸Surveillance includes keylogging, screenshots, webcam, and audio capture.
- ▸System reconnaissance enumerates hardware, software, and security products.
- ▸Remote control includes shell execution, file management, and payload download.
- ▸Impact functions include file encryption and forced shutdown — but it is not primarily ransomware.

