IOC Intelligence Center
Millenium RAT Indicators of Compromise
A professional threat-intelligence database of defanged indicators. Filter by version, type, source, and confidence. Copy individual IOCs or export the full set as CSV/JSON for defensive detection and TI platforms.
Notice: Indicators are historical observations, not permanent proof of maliciousness. Infrastructure can change ownership and file hashes can become obsolete. Always validate indicators in context. All domains and URLs are defanged.
| Indicator | Type | Version | First reported | Source | Confidence | Status | |
|---|---|---|---|---|---|---|---|
| %APPDATA%\<random>\svchost.exe | Filename | 4.x | 2026-06-25 | Group-IB | medium | active | |
| HKCU\Software\Microsoft\Windows\CurrentVersion\Run | Registry | 2.x / 4.x | 2026-06-25 | Group-IB | high | active | |
| api.telegram.org/bot<token>/getUpdates | Network Behavior | 2.x / 4.x | 2026-06-25 | Group-IB | high | active | |
| MsEdgeUpdate.exe | Filename | 4.x | 2026-06-25 | Group-IB | medium | active | |
| rcsdriver3.exe | Filename | 4.x | 2026-06-25 | Group-IB | medium | active | |
| 6d207c1e954f9d60f693e17e63df73fb8e954d02544b5d52b8b18c4ab86a267e | SHA-256 | 2.4 | 2023-11-03 | CYFIRMA | high | historical | |
| f4d698ece0ff6af36c1a2e9108ea475518df0aa7 | SHA-1 | 2.4 | 2023-11-03 | CYFIRMA | high | historical | |
| eba4be8ed0e9282976f8ee0b04fb2474 | MD5 | 2.4 | 2023-11-03 | CYFIRMA | high | historical |
Showing 8 of 8 indicators. Data seeded from verified public sources (CYFIRMA, Group-IB). Analysts can add verified hashes from Group-IB, ANY.RUN, and reputable sandboxes via the database.
Detection
How to use these IOCs →
Incident Response
What to do with a hit →
Sources
Where IOCs come from →
Reviewed byCyber Threat Intelligence Research Team·Last verified: 2026-10-04
