Millenium RAT Tech Blueprints
Detection logic, YARA & Sigma rules, and architecture diagrams — defensive blueprints for defenders, not malware code.
What are the Millenium RAT Tech Blueprints? Tech Blueprints are defensive engineering artifacts — YARA rules for static identification, Sigma rules for SIEM detection, architecture diagrams of the infection chain and Telegram C2 flow, and correlated detection logic. They contain no malware source code, no builder, and no operational guidance for attackers.
- 01Blueprints are 100% defensive: detection rules, diagrams, and correlation logic only.
- 02YARA targets observable strings and behavior, not weaponized code.
- 03Sigma rules map to MITRE ATT&CK techniques (T1547.010, T1036, T1071.001).
- 04Architecture diagrams show the documented infection chain and C2 flow.
- 05All rules are starter templates — validate in your environment before production deployment.
Infection Chain Blueprint
The documented execution path from initial lure to persistent C2 beaconing. Each stage maps to a detection opportunity.
Detection opportunities exist at every stage: block at the drop, alert at persistence, and catch the C2 beacon before exfiltration completes.
Telegram C2 Flow Blueprint
How Millenium RAT abuses the legitimate Telegram Bot API as a command-and-control channel. Telegram is the abused service, not the attacker.
Defensive note: Detect anomalous Telegram Bot API access by process context — do not blanket-block Telegram, which is legitimate infrastructure.
YARA Rule — Loader String Detection
A starter YARA rule matching observable C2 strings and capability indicators. Tune thresholds and add environment-specific exceptions before production use.
rule Millenium_RAT_Loader_Strings : Trojan RAT Loader
{
meta:
author = "Millenium RAT Intelligence"
description = "Defensive detection of Millenium RAT loader artifacts"
reference = "Group-IB, CYFIRMA public reporting"
date = "2026-06"
severity = "high"
strings:
// Telegram Bot API C2 indicators
$tg_api = "api.telegram.org" ascii
$tg_bot = "/bot" ascii
$tg_getupd = "getUpdates" ascii
$tg_send = "sendMessage" ascii
// libcurl user-agent observed in 4.x builds
$curl_ua = "libcurl" ascii
// Masquerade filenames reported by Group-IB
$masc1 = "MsEdgeUpdate.exe" ascii
$masc2 = "rcsdriver3.exe" ascii
// Persistence target
$runkey = "Software\\Microsoft\\Windows\\CurrentVersion\\Run" ascii
// Capability strings
$cap_key = "keylog" ascii
$cap_scr = "screenshot" ascii
$cap_cam = "webcam" ascii
condition:
// Defensive: require C2 + at least one capability or persistence signal
any of ($tg_*) and (any of ($cap_*) or $runkey or any of ($masc*))
and filesize < 4MB
}Sigma Rules — Endpoint & Network
Three Sigma rules covering the documented persistence, execution, and C2 behaviors. Each maps to MITRE ATT&CK techniques.
1. Persistence — HKCU Run Key
title: Millenium RAT Persistence via HKCU Run Key
id: 7f3a2c1e-1b4d-4e8a-9c2f-0a1b2c3d4e5f
status: experimental
description: >
Detects creation of a Run-key value under HKCU by an unsolicited
process, a persistence mechanism reported for Millenium RAT.
references:
- https://milleniumrat.com/millenium-rat-technical-analysis
author: Millenium RAT Intelligence
date: 2026/06/25
logsource:
product: windows
category: registry_event
detection:
selection:
EventType: SetValue
TargetObject|contains:
- "\\Software\\Microsoft\\Windows\\CurrentVersion\\Run"
- "\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce"
filter_legit:
Image|startswith:
- "C:\\Windows\\System32\\"
- "C:\\Program Files\\"
condition: selection and not filter_legit
fields:
- Image
- TargetObject
- Details
falsepositives:
- Legitimate user-installed software creating autorun entries
level: high
tags:
- attack.persistence
- attack.t1547.010
- attack.t10602. Execution — AppData Loader with Masquerade Name
title: Suspicious Execution from AppData — Millenium RAT Loader Pattern
id: 8b4c3d2f-2c5e-4f9b-ad30-1b2c3d4e5f60
status: experimental
description: >
Detects an executable launched from a user-writable AppData path,
consistent with the Millenium RAT loader dropping itself under a
randomized folder and a masquerade name.
references:
- https://milleniumrat.com/millenium-rat-detection
author: Millenium RAT Intelligence
date: 2026/06/25
logsource:
product: windows
category: process_creation
detection:
selection:
Image|startswith:
- "C:\\Users\\*\\AppData\\Roaming\\"
- "C:\\Users\\*\\AppData\\Local\\"
Image|endswith:
- ".exe"
filter_masquerade:
Image|endswith:
- "MsEdgeUpdate.exe"
- "rcsdriver3.exe"
- "svchost.exe"
condition: selection and filter_masquerade
fields:
- Image
- ParentImage
- CommandLine
falsepositives:
- Unlikely for these specific masquerade names outside system paths
level: critical
tags:
- attack.defense_evasion
- attack.t1036
- attack.execution3. Command & Control — Telegram Bot API
title: Outbound Telegram Bot API Connection from Non-Telegram Process
id: 9c5d4e3a-3d6f-4a0c-be41-2c3d4e5f6071
status: experimental
description: >
Detects an unexpected process contacting the Telegram Bot API,
the documented command-and-control channel for Millenium RAT.
references:
- https://milleniumrat.com/millenium-rat-telegram-c2
author: Millenium RAT Intelligence
date: 2026/06/25
logsource:
product: windows
category: network_connection
detection:
selection:
DestinationHostname|contains:
- "api.telegram.org"
Initiated: "true"
filter_legit:
Image|endswith:
- "\\Telegram.exe"
- "\\Telegram Desktop\\Telegram.exe"
condition: selection and not filter_legit
fields:
- Image
- DestinationHostname
- DestinationPort
falsepositives:
- Legitimate automation using the Telegram Bot API
level: high
tags:
- attack.command_and_control
- attack.t1105
- attack.t1071.001Correlated Detection Blueprint
No single rule is sufficient. Correlate the three Sigma signals within a short time window to raise confidence and reduce false positives.
// Pseudo-correlation logic for SIEM / EDR
rule Millenium_RAT_Correlated {
within: 10m
events:
e1: sigma_appdata (process from AppData + masquerade name)
e2: sigma_runkey (HKCU Run key created)
e3: sigma_telegram (Telegram Bot API connection)
condition:
// Strong RAT signal: loader + persistence + C2
e1 and e2 and e3
// Medium signal: any two of three, raise for analyst review
or (2 of (e1, e2, e3))
action:
raise incident "Millenium RAT — correlated detection"
quarantine host
trigger incident-response playbook
}Scope: These blueprints are defensive detection artifacts only. They do not include, and will never include, malware source code, builder logic, or operational guidance for attackers.
- ▸Blueprints are defensive: YARA + Sigma + correlation logic, no malware code.
- ▸Correlate AppData execution + Run key + Telegram C2 for highest confidence.
- ▸Map every rule to MITRE ATT&CK for tracking and reporting.
- ▸Validate and tune rules in your environment before production deployment.
Detection Guide
MITRE ATT&CK Mapping
IOC Database

