Millenium RAT's public history begins on November 3, 2023, when CYFIRMA published a major analysis of version 2.4 — a .NET Win32 executable using Telegram C2. Version 2.5 was reported shortly after. Broadcom/Symantec published protection information the same month.
Through 2024 and 2025, continued public sightings and malware-analysis reports appeared. Public sandbox records showed newer 4.x samples in circulation in 2025, and the native C++ rewrite became apparent. In 2026, the native C++ branch became the primary subject of new research.
Group-IB telemetry recorded 39,730 infections during Q1 2026. On June 25, 2026, Group-IB published its major Millenium RAT 4.x analysis, reporting cumulative telemetry of 62,289 endpoints across 160+ countries. This timeline is maintained and updated as new verified research emerges.
