njRAT is one of the longer-standing Windows remote-access trojans, historically a .NET family with custom command-and-control infrastructure. Millenium RAT is a newer family that abuses the Telegram Bot API for C2 and was rewritten in native C++ in its 4.x branch.
Group-IB observed trojanized packages masquerading as njRAT being used to deliver Millenium RAT, again illustrating criminal-to-criminal targeting. The two families represent different eras and architectures of RAT development: njRAT's custom C2 versus Millenium RAT's cloud-platform-abuse model.
Defensively, njRAT detection focuses on its established C2 protocol signatures, while Millenium RAT detection focuses on Telegram Bot API anomalies and AppData persistence. Both benefit from behavioral correlation over hash-only detection.
