How to Detect Millenium RAT
Layered detection across endpoint, network, and behavioral correlation — why a single hash or a single IOC is not enough.
How can companies detect Millenium RAT? Detect Millenium RAT by correlating endpoint signals (executables launched from AppData, new HKCU Run keys, browser-credential-store access) with network signals (unexpected Telegram Bot API traffic from processes that should not access Telegram) and behavior. Hash-only detection is insufficient because builds vary hashes through configuration padding.
1. Endpoint detection
Watch for combinations involving:
- ▸Executables launched from user-writable AppData directories
- ▸Suspicious system-process names outside legitimate system paths
- ▸Unusual autorun creation
- ▸Suspicious registry Run-key modifications
- ▸Browser-credential-store access
- ▸Webcam/microphone access by unexpected software
- ▸Keylogging-like behavior
- ▸Suspicious security-tool interaction
2. Network detection
Look for:
- ▸Unexpected Telegram Bot API communication from processes that normally should not access Telegram
- ▸Repeated HTTPS polling behavior
- ▸Suspicious traffic involving known campaign infrastructure
- ▸Unexpected large data transfers
- ▸Unusual cloud / file-hosting uploads
Important: Do not simply block all Telegram traffic universally. Organizations should make policy decisions based on business requirements.
3. Behavioral correlation
Example correlated detection logic:
Correlated behavioral detection is superior to a single IOC because it survives hash variation and infrastructure rotation.
4. Hash detection — and its limits
Hashes identify known-bad samples quickly and are worth maintaining in blocklists.
Group-IB observed configuration-padding techniques that cause file-hash variation between builds even when functionality is similar. Hash-only detection misses these.
- ▸Correlate endpoint + network + behavioral signals for higher confidence.
- ▸AppData execution + Run key + Telegram API + credential access = strong RAT signal.
- ▸Do not block all Telegram; detect anomalous access by process context.
- ▸Hashes are useful but insufficient due to config padding.

