Join our Telegram channel @MilleniumRatcom for the latest Millenium RAT intelligence updates.

Capabilities

Millenium RAT Capability Matrix

Reported capabilities organized by category — what the malware can do on a compromised Windows endpoint.

Answer

What can Millenium RAT do? Millenium RAT can steal browser credentials, cookies, history, payment-card data, Discord tokens, Telegram data and cryptocurrency wallets; perform keylogging, screenshot, webcam and audio capture; reconnaissance of system hardware and security products; remote control including shell execution and file management; and disruptive functions including file encryption and forced shutdown. Capabilities are summarized by function and security impact, not as an operator manual.

Information Stealing

11 items
  • ▸Browser credentials
  • ▸Browser cookies
  • ▸Browsing history
  • ▸Stored browser information
  • ▸Downloaded-file metadata
  • ▸Saved payment-card information (where available)
  • ▸Desktop / user files
  • ▸System information
  • ▸Discord session / token information
  • ▸Telegram-related information
  • ▸Cryptocurrency / browser-extension wallet data (newer versions)

Surveillance

5 items
  • ▸Keylogging
  • ▸Screenshot capture
  • ▸Webcam capture
  • ▸Microphone / audio capture
  • ▸Active-window information

System Reconnaissance

9 items
  • ▸Username & administrator status
  • ▸Operating-system information
  • ▸CPU / GPU
  • ▸Installed RAM
  • ▸Hardware identifier
  • ▸System architecture
  • ▸Installed programs
  • ▸Antivirus / security-product information
  • ▸Running processes

Remote Access / Control

9 items
  • ▸Remote process interaction
  • ▸File management
  • ▸Opening URLs
  • ▸Executing files
  • ▸Downloading additional payloads
  • ▸Remote shell / command execution
  • ▸PowerShell-related execution capability
  • ▸System restart / shutdown / logoff
  • ▸UI manipulation

Collection & Exfiltration

4 items
  • ▸File collection
  • ▸Archiving of collected data
  • ▸Exfiltration via Telegram infrastructure
  • ▸Larger-file transfers via third-party file-transfer infrastructure

Impact / Disruptive Functions

6 items
  • ▸File encryption / decryption functionality
  • ▸Deletion / manipulation of files
  • ▸Forced shutdown / restart
  • ▸System disruption
  • ▸Blue Screen (BSOD) triggering
  • ▸Display manipulation

Is Millenium RAT ransomware?

No — not by default. Researchers documented file encryption/decryption functionality, but the presence of encryption does not mean every Millenium RAT infection becomes a ransomware incident. Millenium RAT is primarily a remote-access trojan and infostealer. The encryption capability is one of several impact functions, not the malware's core purpose.

Key Takeaways
  • ▸Information stealing spans browsers, Discord, Telegram, and crypto wallets.
  • ▸Surveillance includes keylogging, screenshots, webcam, and audio capture.
  • ▸System reconnaissance enumerates hardware, software, and security products.
  • ▸Remote control includes shell execution, file management, and payload download.
  • ▸Impact functions include file encryption and forced shutdown — but it is not primarily ransomware.
Reviewed byCyber Threat Intelligence Research Team·Last verified: 2026-10-04
Millenium RAT Full Tech package — 0.10 BTC — contact for access