Group-IB publishes major Millenium RAT 4.x analysis
Group-IB documents the native C++ rewrite, libcurl Telegram C2, MaaS pricing, and 62,289 endpoints across 160+ countries.
Join our Telegram channel @MilleniumRatcom for the latest Millenium RAT intelligence updates.
A continuously updated threat-intelligence newsroom. Each item is sourced, dated, version-tagged, and confidence-rated. Items reflect the state of public reporting as of their publication date.
Group-IB documents the native C++ rewrite, libcurl Telegram C2, MaaS pricing, and 62,289 endpoints across 160+ countries.
Group-IB telemetry records infections during Q1 2026, ahead of the June 2026 major analysis.
ANY.RUN and other public sandboxes begin recording newer Millenium RAT 4.x samples; native rewrite becomes apparent.
Symantec documents remote control, keylogging, screenshots, browser-data theft, and Telegram exfiltration.
CYFIRMA publishes the first major public analysis of Millenium RAT 2.4, a .NET Win32 Telegram RAT with ToxicEye lineage.
