Live Threat Profile

Millenium RATComplete Threat Intelligence & Malware Analysis

An independent defensive intelligence resource covering Millenium RAT architecture, versions, Telegram command-and-control, campaigns, indicators of compromise, detection, MITRE ATT&CK mapping and incident response.

Also searched as Millennium RAT — both spellings refer to the same malware family.
Threat Profile
Category
Remote Access Trojan / Infostealer
Platform
Windows
Generation
4.x
Architecture
Native C++
C2
Telegram Bot API
Developer alias
ShinyEnigma
Op. cluster
Y2K Operators
First reporting
November 2023
Data source: Group-IB · Published June 25, 2026
62,289
Endpoints identified
Group-IB telemetry
160+
Countries affected
Reported reach
39,730
Q1 2026 infections
Group-IB
Windows
Primary platform
Telegram
C2 infrastructure
Bot API (abused)
Native C++
v4.x architecture
Earlier: .NET

Statistics reflect Group-IB telemetry published June 25, 2026. Telemetry provides visibility into part of the ecosystem; counts may not represent every compromised device.

What is Millenium RAT?

A Windows RAT rewritten for scale

Answer

What is Millenium RAT? Millenium RAT is a Windows remote-access trojan and information-stealing malware family first publicly analyzed in 2023. It enables unauthorized remote control, credential and browser-data theft, keylogging, screenshots and other surveillance functions. Newer 4.x versions were rewritten in native C++ and use Telegram Bot API infrastructure for command-and-control. Group-IB reported more than 62,000 compromised endpoints across 160+ countries.

First documented by CYFIRMA in November 2023 as a .NET Win32 executable, Millenium RAT has since undergone a substantial architectural rewrite. According to Group-IB's June 2026 research, the 4.x branch is a native C++ application that uses libcurl to communicate with the Telegram Bot API, marketed under a low-cost Malware-as-a-Service model. This combination — cheap access, broad opportunistic distribution, and Telegram-abused C2 — explains the tens of thousands of compromised endpoints observed.

This portal documents Millenium RAT purely for defensive purposes: detection, incident response, and threat intelligence. It does not host malware, source code, or weaponization instructions.

Key Facts
  • 01First publicly analyzed by CYFIRMA on November 3, 2023 (v2.4, .NET).
  • 024.x branch rewritten in native C++ (Group-IB, June 2026).
  • 03Telegram Bot API abused for command-and-control and exfiltration.
  • 0462,289 endpoints / 160+ countries in Group-IB telemetry.
  • 05Developer alias: ShinyEnigma. Operational cluster: Y2K Operators.
  • 06Marketed as Malware-as-a-Service (~US$50 first month).
Evolution

From .NET 2.x to native C++ 4.x

The defining shift in Millenium RAT's history is the architectural rewrite from managed .NET code to a compiled native C++ application — changing how defenders must analyze and detect it.

Earlier generation2.x
Architecture
.NET (managed)
Platform
Windows
C2
Telegram Bot API
Analyzed
Nov 2023

Managed-code architecture dependent on the .NET Framework. Detectable via .NET static-analysis tooling.

Newer generation4.x
Architecture
Native C++
Platform
Windows
C2
Telegram (libcurl)
Analyzed
June 2026

Removes .NET dependency, changes static-analysis characteristics and signatures, alters reverse-engineering workflows. C++ does not automatically make it undetectable.

How it works

The Millenium RAT infection chain

A high-level, safe visualization of the publicly documented campaign flow — from social-engineering lure to Telegram-based exfiltration and remote control.

01
Social-engineering lure
↓
02
Archive / disguised file
↓
03
User execution
↓
04
Scripting / staging
↓
05
Decoy may appear
↓
06
Payload executes
↓
07
Persistence
↓
08
Telegram C2
↓
09
Collection / control

Telegram C2

HTTPS to Telegram Bot API blends into normal cloud traffic; little dedicated attacker infrastructure needed.

Persistence

Copies into AppData and creates HKCU Run-key autorun with configurable filenames.

Exfiltration

Collected data archived and sent via Telegram; larger transfers via third-party file-transfer infrastructure.

Capability matrix

What Millenium RAT can do

Reported capabilities span information theft, surveillance, reconnaissance, remote control, collection, and disruptive impact functions.

Information Stealing

11
  • · Browser credentials
  • · Browser cookies
  • · Browsing history
  • · Stored browser information
  • · Downloaded-file metadata
  • +6 more

Surveillance

5
  • · Keylogging
  • · Screenshot capture
  • · Webcam capture
  • · Microphone / audio capture
  • · Active-window information

System Reconnaissance

9
  • · Username & administrator status
  • · Operating-system information
  • · CPU / GPU
  • · Installed RAM
  • · Hardware identifier
  • +4 more

Remote Access / Control

9
  • · Remote process interaction
  • · File management
  • · Opening URLs
  • · Executing files
  • · Downloading additional payloads
  • +4 more

Collection & Exfiltration

4
  • · File collection
  • · Archiving of collected data
  • · Exfiltration via Telegram infrastructure
  • · Larger-file transfers via third-party file-transfer infrastructure

Impact / Disruptive Functions

6
  • · File encryption / decryption functionality
  • · Deletion / manipulation of files
  • · Forced shutdown / restart
  • · System disruption
  • · Blue Screen (BSOD) triggering
  • +1 more
Full capability matrix
Global campaign statistics

Reported reach: 160+ countries

Group-IB publicly highlighted India, the United States, and Brazil among major affected geographies. Reported activity spans more than 160 countries; exact per-country totals depend on available telemetry.

India
Highlighted by Group-IB among most-affected geographies
United States
Highlighted by Group-IB among most-affected geographies
Brazil
Highlighted by Group-IB among most-affected geographies
Telemetry caveat: Security-company telemetry provides visibility into part of the ecosystem. Infection counts may not represent every compromised device. Never present these as the definitive total of every Millenium RAT infection worldwide.
Campaigns & victimology
MITRE ATT&CK preview

Mapped techniques

Millenium RAT behavior maps across Initial Access, Execution, Persistence, Credential Access, Discovery, Defense Evasion, Collection, Exfiltration, and Impact.

T1566 PhishingT1204 User ExecutionT1059 Command and Scripting InterpreterT1547.001 Registry Run Keys / Startup FolderT1056 Input CaptureT1555.003 Credentials from Web BrowsersT1057 Process DiscoveryT1083 File and Directory DiscoveryT1033 System Owner/User DiscoveryT1082 System Information DiscoveryT1518.001 Software Discovery: Security SoftwareT1497 Virtualization/Sandbox EvasionT1036 MasqueradingT1027 Obfuscated Files or InformationT1113 Screen CaptureT1123 Audio Capture
Full ATT&CK mapping
Detection & response

Correlation beats a single hash

Group-IB observed configuration-padding techniques that cause file-hash variation between builds even when underlying functionality is similar. Hash-only detection is insufficient. Modern defenders correlate file reputation, behavioral activity, process lineage, persistence, and network communication.

Endpoint: AppData execution + new Run key + browser-credential access
Network: unexpected Telegram Bot API traffic from non-browser processes
Behavior: correlated signals = higher-confidence RAT detection
Correlated detection logic
01Process running from AppData
02New HKCU Run key created
03Telegram API connection
04Browser credential access
=
Higher-confidence RAT signal
FAQ

Common questions

What is Millenium RAT?

Millenium RAT is a Windows remote-access trojan and information-stealing malware family first publicly analyzed in 2023. It enables unauthorized remote control, credential and browser-data theft, keylogging, screenshots and surveillance. Newer 4.x versions were rewritten in native C++ and use the Telegram Bot API for command-and-control. Group-IB reported more than 62,000 compromised endpoints across 160+ countries.

Is Millenium RAT malware?

Yes. Millenium RAT is malicious software classified as a Remote Access Trojan (RAT) and infostealer. Despite being marketed with 'educational purposes' disclaimers, researchers consider its functionality clearly suitable for malicious abuse.

Is Millenium RAT a Remote Access Trojan?

Yes. Millenium RAT is a RAT — it provides an attacker with unauthorized remote control of a compromised Windows machine, alongside information-stealing and surveillance capabilities.

Is Millenium RAT the same as Millennium RAT?

Yes. The malware is predominantly referred to by researchers as 'Millenium RAT,' but many users search for 'Millennium RAT.' Both spellings refer to the same malware family. This resource covers both spellings.

Who created Millenium RAT?

Public researchers associate the developer/marketing identity 'ShinyEnigma' with Millenium RAT. No real-world identity has been reliably established by authoritative evidence. ShinyEnigma is an online alias / developer handle, not a confirmed individual.

Who is ShinyEnigma?

ShinyEnigma is the online alias / developer handle associated by public researchers with the development and marketing of Millenium RAT. Attribution beyond the moniker is not established.

Who are the Y2K Operators?

Y2K Operators is the name Group-IB uses to track a threat cluster associated with active Millenium RAT deployment and distribution campaigns. It is distinct from ShinyEnigma (development/marketing) and should not be assumed to be the same entity.

When was Millenium RAT discovered?

CYFIRMA published the first major public analysis of Millenium RAT on November 3, 2023, focusing on version 2.4. Broadcom/Symantec published protection information the same month.

All FAQs