{
  "family": "njrat",
  "sample_count": 19,
  "category": "rat",
  "description": "njRAT is a remote access tool (RAT) that, per MITRE ATT&CK, was first observed in 2012 and has been used by threat actors in the Middle East and more broadly. Because its builder tools circulated widely, it has been adopted by a large range of low- to mid-tier actors. It gives an attacker remote control of an infected machine, including keylogging, credential theft, file access, and webcam/microphone access. It is also tracked under the detection name Bladabindi.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "njRAT",
    "Bladabindi",
    "Njw0rm",
    "LV"
  ],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What is njRAT?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "A remote access trojan first seen in 2012 that gives attackers full remote control of an infected computer."
      }
    },
    {
      "@type": "Question",
      "name": "Is njRAT the same as Bladabindi?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes. Bladabindi is a common detection name many vendors use for the njRAT family (MITRE tracks them as the same software, S0385)."
      }
    },
    {
      "@type": "Question",
      "name": "What can njRAT do?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Remote control, keylogging, credential theft, file browsing and transfer, and webcam/microphone access."
      }
    },
    {
      "@type": "Question",
      "name": "Why is njRAT so widespread?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Its builder tools spread widely, making it easy for many different actors to create and deploy their own variants."
      }
    },
    {
      "@type": "Question",
      "name": "How does njRAT spread?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Typically through phishing, malicious downloads, pirated software, and infected USB drives."
      }
    },
    {
      "@type": "Question",
      "name": "What are njRAT's other aliases?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It is also tracked as Bladabindi, Njw0rm, and LV."
      }
    },
    {
      "@type": "Question",
      "name": "How do I reduce the risk of RATs like njRAT?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Avoid pirated software and untrusted downloads, be cautious with attachments, keep endpoint protection updated, and disable autorun on removable media."
      }
    },
    {
      "@type": "Question",
      "name": "Where is the authoritative reference?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "MITRE ATT&CK's njRAT entry (S0385), linked on this page."
      }
    }
  ],
  "faq_count": 8,
  "mitre_attack": [
    "T1056.001",
    "T1547.001",
    "T1071.001"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-06-09",
  "sources": [
    {
      "name": "MITRE ATT&CK: njRAT (S0385)",
      "url": "https://attack.mitre.org/software/S0385"
    }
  ],
  "mitre_url": "https://attack.mitre.org/software/S0385",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}