Inside Millenium RAT
Architecture, configuration, persistence, masquerading, and anti-analysis — from the .NET 2.x lineage to the native C++ 4.x rewrite.
What is the technical architecture of Millenium RAT? Millenium RAT 4.x is a native C++ Windows application that stores its configuration inside an embedded PE RCDATA resource, decoded at runtime from Base64 plus a custom XOR-based protection. It uses libcurl to communicate with the Telegram Bot API for command-and-control and exfiltration, and maintains persistence via the HKCU Run registry key from an AppData directory.
Architectural evolution
- Managed-code Win32 executable
- Dependent on the .NET Framework
- Detectable via .NET static-analysis tooling (decompilers, dnLib-style tooling)
- Structural similarity to ToxicEye Telegram RAT (CYFIRMA)
- Compiled native Windows application
- Removes the .NET Framework dependency
- Changes static-analysis characteristics and signatures
- Uses libcurl for Telegram API communication
- Alters reverse-engineering workflows
Note: native C++ does not automatically make malware "undetectable." It changes the analysis workflow and reduces the value of detections that specifically targeted earlier .NET implementations.
Configuration architecture (4.x)
According to Group-IB, Millenium RAT 4.x stores configuration data inside an embedded Windows PE RCDATA resource. Reported processing:
Researchers observed additional random Base64 content placed alongside configuration data. This can alter resulting file hashes between builds even when underlying functionality remains similar — a key reason hash-only malware detection is insufficient.
Hash-based vs. behavior-based detection
- Matches a known file fingerprint
- Breaks when builds vary hashes (config padding)
- Useful but insufficient on its own
- Correlates file reputation, behavior, process lineage
- Persistence, network communication, endpoint telemetry
- Survives hash variation between builds
Persistence
Public research documents Millenium RAT copying itself into a directory beneath the user's AppData area and creating Windows autorun persistence via the HKCU Run registry mechanism, with malware-configurable filenames and directories.
C:\Windows\System32\svchost.exe%APPDATA%\...\svchost.exeIllustrative example only. No persistence-creation script is provided.
Masquerading
Group-IB observed payload names resembling legitimate system/software processes. Filenames alone cannot establish maliciousness — the important indicators are location, signing, parent process, persistence, and network behavior.
Anti-analysis & defense evasion
Older Millenium RAT research documented checks for virtualized environments (VMware, VirtualBox), sandboxes, debuggers, and security/analysis software. Newer versions continue to include sandbox/security-product awareness. Automated malware-analysis environments are widely used by defenders; attackers sometimes attempt to change behavior when analysis environments are detected.
- ▸4.x is a native C++ rewrite that removes the .NET dependency.
- ▸Config is embedded as Base64 + custom XOR in a PE RCDATA resource.
- ▸Config padding causes hash variation — hash-only detection is insufficient.
- ▸Persistence uses AppData + HKCU Run key with configurable names.
- ▸Anti-analysis includes sandbox/VM/debugger checks.

