Millenium RATComplete Threat Intelligence & Malware Analysis
An independent defensive intelligence resource covering Millenium RAT architecture, versions, Telegram command-and-control, campaigns, indicators of compromise, detection, MITRE ATT&CK mapping and incident response.
- Category
- Remote Access Trojan / Infostealer
- Platform
- Windows
- Generation
- 4.x
- Architecture
- Native C++
- C2
- Telegram Bot API
- Developer alias
- ShinyEnigma
- Op. cluster
- Y2K Operators
- First reporting
- November 2023
Statistics reflect Group-IB telemetry published June 25, 2026. Telemetry provides visibility into part of the ecosystem; counts may not represent every compromised device.
A Windows RAT rewritten for scale
What is Millenium RAT? Millenium RAT is a Windows remote-access trojan and information-stealing malware family first publicly analyzed in 2023. It enables unauthorized remote control, credential and browser-data theft, keylogging, screenshots and other surveillance functions. Newer 4.x versions were rewritten in native C++ and use Telegram Bot API infrastructure for command-and-control. Group-IB reported more than 62,000 compromised endpoints across 160+ countries.
First documented by CYFIRMA in November 2023 as a .NET Win32 executable, Millenium RAT has since undergone a substantial architectural rewrite. According to Group-IB's June 2026 research, the 4.x branch is a native C++ application that uses libcurl to communicate with the Telegram Bot API, marketed under a low-cost Malware-as-a-Service model. This combination — cheap access, broad opportunistic distribution, and Telegram-abused C2 — explains the tens of thousands of compromised endpoints observed.
This portal documents Millenium RAT purely for defensive purposes: detection, incident response, and threat intelligence. It does not host malware, source code, or weaponization instructions.
- 01First publicly analyzed by CYFIRMA on November 3, 2023 (v2.4, .NET).
- 024.x branch rewritten in native C++ (Group-IB, June 2026).
- 03Telegram Bot API abused for command-and-control and exfiltration.
- 0462,289 endpoints / 160+ countries in Group-IB telemetry.
- 05Developer alias: ShinyEnigma. Operational cluster: Y2K Operators.
- 06Marketed as Malware-as-a-Service (~US$50 first month).
From .NET 2.x to native C++ 4.x
The defining shift in Millenium RAT's history is the architectural rewrite from managed .NET code to a compiled native C++ application — changing how defenders must analyze and detect it.
- Architecture
- .NET (managed)
- Platform
- Windows
- C2
- Telegram Bot API
- Analyzed
- Nov 2023
Managed-code architecture dependent on the .NET Framework. Detectable via .NET static-analysis tooling.
- Architecture
- Native C++
- Platform
- Windows
- C2
- Telegram (libcurl)
- Analyzed
- June 2026
Removes .NET dependency, changes static-analysis characteristics and signatures, alters reverse-engineering workflows. C++ does not automatically make it undetectable.
The Millenium RAT infection chain
A high-level, safe visualization of the publicly documented campaign flow — from social-engineering lure to Telegram-based exfiltration and remote control.
Telegram C2
HTTPS to Telegram Bot API blends into normal cloud traffic; little dedicated attacker infrastructure needed.
Persistence
Copies into AppData and creates HKCU Run-key autorun with configurable filenames.
Exfiltration
Collected data archived and sent via Telegram; larger transfers via third-party file-transfer infrastructure.
What Millenium RAT can do
Reported capabilities span information theft, surveillance, reconnaissance, remote control, collection, and disruptive impact functions.
Information Stealing
11- · Browser credentials
- · Browser cookies
- · Browsing history
- · Stored browser information
- · Downloaded-file metadata
- +6 more
Surveillance
5- · Keylogging
- · Screenshot capture
- · Webcam capture
- · Microphone / audio capture
- · Active-window information
System Reconnaissance
9- · Username & administrator status
- · Operating-system information
- · CPU / GPU
- · Installed RAM
- · Hardware identifier
- +4 more
Remote Access / Control
9- · Remote process interaction
- · File management
- · Opening URLs
- · Executing files
- · Downloading additional payloads
- +4 more
Collection & Exfiltration
4- · File collection
- · Archiving of collected data
- · Exfiltration via Telegram infrastructure
- · Larger-file transfers via third-party file-transfer infrastructure
Impact / Disruptive Functions
6- · File encryption / decryption functionality
- · Deletion / manipulation of files
- · Forced shutdown / restart
- · System disruption
- · Blue Screen (BSOD) triggering
- +1 more
Reported reach: 160+ countries
Group-IB publicly highlighted India, the United States, and Brazil among major affected geographies. Reported activity spans more than 160 countries; exact per-country totals depend on available telemetry.
Mapped techniques
Millenium RAT behavior maps across Initial Access, Execution, Persistence, Credential Access, Discovery, Defense Evasion, Collection, Exfiltration, and Impact.
Correlation beats a single hash
Group-IB observed configuration-padding techniques that cause file-hash variation between builds even when underlying functionality is similar. Hash-only detection is insufficient. Modern defenders correlate file reputation, behavioral activity, process lineage, persistence, and network communication.
Common questions
What is Millenium RAT?
Millenium RAT is a Windows remote-access trojan and information-stealing malware family first publicly analyzed in 2023. It enables unauthorized remote control, credential and browser-data theft, keylogging, screenshots and surveillance. Newer 4.x versions were rewritten in native C++ and use the Telegram Bot API for command-and-control. Group-IB reported more than 62,000 compromised endpoints across 160+ countries.
Is Millenium RAT malware?
Yes. Millenium RAT is malicious software classified as a Remote Access Trojan (RAT) and infostealer. Despite being marketed with 'educational purposes' disclaimers, researchers consider its functionality clearly suitable for malicious abuse.
Is Millenium RAT a Remote Access Trojan?
Yes. Millenium RAT is a RAT — it provides an attacker with unauthorized remote control of a compromised Windows machine, alongside information-stealing and surveillance capabilities.
Is Millenium RAT the same as Millennium RAT?
Yes. The malware is predominantly referred to by researchers as 'Millenium RAT,' but many users search for 'Millennium RAT.' Both spellings refer to the same malware family. This resource covers both spellings.
Who created Millenium RAT?
Public researchers associate the developer/marketing identity 'ShinyEnigma' with Millenium RAT. No real-world identity has been reliably established by authoritative evidence. ShinyEnigma is an online alias / developer handle, not a confirmed individual.
Who is ShinyEnigma?
ShinyEnigma is the online alias / developer handle associated by public researchers with the development and marketing of Millenium RAT. Attribution beyond the moniker is not established.
Who are the Y2K Operators?
Y2K Operators is the name Group-IB uses to track a threat cluster associated with active Millenium RAT deployment and distribution campaigns. It is distinct from ShinyEnigma (development/marketing) and should not be assumed to be the same entity.
When was Millenium RAT discovered?
CYFIRMA published the first major public analysis of Millenium RAT on November 3, 2023, focusing on version 2.4. Broadcom/Symantec published protection information the same month.