Millenium RAT v4.x — Native C++ Telegram-Controlled Remote Access Trojan & Infostealer Sold as Malware-as-a-Service (ShinyEnigma)

Millenium RAT v4.x (TL-2026-0942), also tracked as Millenium RAT, is a critical-severity malware campaign, first published 2026-06-25. It is attributed to ShinyEnigma with medium confidence, affects Microsoft Windows, maps to 37 MITRE ATT&CK techniques (T1005, T1012, T1027), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-0942

Threat ID
TL-2026-0942
Also known as
Millenium RAT, Millennium RAT, Millenium Stealer
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
2026-06-25
Last reviewed
2026-06-25
Attribution
ShinyEnigma
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
consumer, gaming, cryptocurrency, technology, financial
Target regions
Global, Russia, North America, Europe, Asia
Detection rules
9
Indicators of compromise
30

Malware and tooling in Millenium RAT v4.x

Malware and tooling: Telegram Bot API (getUpdates polling)

Millenium RAT is a Windows Remote Access Trojan and infostealer distributed as Malware-as-a-Service by the actor 'ShinyEnigma'. Group-IB reports version 4.x was rewritten from .NET to a native C++ application, removing the .NET runtime dependency while retaining serverless Telegram Bot API command-and-control. The operation is tied to 62,289 compromised endpoints across 160+ countries, with 39,730 infections (63.8%) in Q1 2026 alone.

How Millenium RAT v4.x works

Millenium RAT is a commodity Windows Remote Access Trojan and credential/cryptocurrency stealer marketed as a low-cost Malware-as-a-Service (MaaS) by an actor using the handle 'ShinyEnigma' (also 'shinyenigma'), with active exploitation attributed by Group-IB to a cluster tracked as 'Y2K Operators'. The malware first surfaced in November 2023 (CYFIRMA, version 2.4), where it was assessed as a derivative of the open-source ToxicEye Telegram RAT, sharing structure, modules, namespaces and function names. By June 2026 the project had been rewritten: Group-IB's 25 June 2026 analysis documents version 4.x as a native C++ application compiled to a standalone PE, eliminating the .NET Framework runtime dependency present in earlier builds and reducing detection surface.

C2 is serverless: rather than operating dedicated infrastructure, each build communicates with the Telegram Bot API over HTTPS using the getUpdates polling method, with an embedded bot token and chat id. Operator commands are issued through the Telegram chat in the form /[4-digit-botid]*command*parameter1*parameter2, exposing 50+ implemented functions. Configuration is stored in an embedded PE RCDATA resource as a Base64-encoded, custom-XOR-encrypted blob containing fields including token, id, name (used simultaneously as the mutex identifier and HKCU registry value name), start_delay, query_delay, keylog_filename, install_foldername, and boolean feature flags persist, keylogger, elevate, auto_steal and detect_sandbox.

Capabilities span the full RAT/stealer feature set: extraction of browser-stored passwords, cookies and history; theft of Telegram and Discord session/token data; cryptocurrency wallet and browser-extension wallet recovery ('walletRecovery'); keylogging; screenshot capture; 15-second audio recording; webcam access; and host reconnaissance (administrator-privilege check, CPU/GPU, total RAM, Hardware ID, Windows version, architecture, antivirus status, installed software). Destructive/impact functions include file encryption and decryption, system shutdown and restart, BSOD triggering, and display rotation. Persistence is achieved via an HKCU\Software\Microsoft\Windows\CurrentVersion\Run autorun entry and installation of the executable into a %APPDATA% subfolder, with an HKCU\Software\[name] semaphore key tracking first-versus-subsequent execution. Anti-analysis features include sandbox and AV/EDR detection, Windows Defender preference modification, configuration obfuscation, and a self-uninstall routine.

Distribution relies on social-engineering lures hosted on attacker-controlled domains and file hosts: fraud utilities (gift-card/crypto generators), 'hacking toolkits' (OSINT, WiFi cracking), software cracks/KYC-bypass tools, Roblox-themed game cheats, and trojanized builders of other RATs (XWorm, AsyncRAT, njRAT). Payloads are commonly delivered via LNK shortcuts disguised as PDFs, PowerShell downloaders and VBS intermediaries that stage a decoy document while silently executing the RAT. Exfiltration is performed over the Telegram Bot API and the Gofile cloud-storage service, with staged data Base64-encoded. The developer advertised the project on a marketing site (milleniumrat.online), Dread forum posts, and code-hosting repositories on GitHub, GitLab and Gitea; pricing for v4.x is $50 for the first month, $10 for subsequent months, or a one-time $90 lifetime purchase (down-market from the $30 lifetime price of v2.4).

MITRE ATT&CK techniques used in TL-2026-0942

Collection

T1005 Data from Local System; T1056 Input Capture; T1074 Data Staged; T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture; T1560 Archive Collected Data

Discovery

T1012 Query Registry; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1217 Browser Information Discovery; T1518 Software Discovery; T1614 System Location Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution; T1674 Input Injection

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1529 System Shutdown/Reboot

Credential Access

T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Persistence

T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Millenium RAT v4.x

  • Microsoft — Windows
    Vulnerable versions: Windows 10; Windows 11; Windows Server (user endpoints)

Remediation for Millenium RAT v4.x

Immediate actions

  • Block all listed C2/distribution domains and IPs (blackhatusa.com, milleniumrat.online, 75877.mcdir.me, modedapk.net, thesnapchatmodapk.com, kuttabilla.top, 158.94.208.168, 62.60.226.97, 130.12.180.43) at perimeter and DNS resolvers
  • Alert on outbound HTTPS to api.telegram.org/bot*/getUpdates from non-sanctioned hosts and on traffic to gofile.io upload endpoints
  • Hunt for HKCU\Software\Microsoft\Windows\CurrentVersion\Run autorun values pointing into %APPDATA% subfolders and quarantine matching SHA256 samples
  • Block execution of the listed lure filenames and masquerading binaries (svchost.exe, MsEdgeUpdate.exe, Microsoft Antivirus.exe, MSAV.exe, rcsdriver.exe) from user-writable paths

Workarounds

  • Disable Windows Script Host (wscript/cscript) where not required to break VBS staging
  • Enable Defender tamper protection to resist preference modification

Longer-term hardening

  • Deploy EDR with behavioral detection for LNK-to-PowerShell-to-VBS execution chains and credential-store/clipboard access
  • Enforce application allow-listing (WDAC/AppLocker) to prevent execution of unsigned binaries from %APPDATA% and Downloads
  • User awareness training targeting cracked-software, game-cheat and 'hacking tool' lures
  • Restrict and monitor Telegram API egress; treat unexpected api.telegram.org traffic as suspicious

Timeline of Millenium RAT v4.x

  • CYFIRMA's first public report documents Millenium RAT version 2.4 as a .NET-based commodity infostealer/RAT advertised on underground forums, establishing the malware family's pre-C++ lineage.
  • CYFIRMA publishes first public report on Millenium RAT (version 2.4), assessing it as a derivative of the open-source ToxicEye Telegram RAT; advertised at $30 lifetime.
  • Deepwatch Cyber Intel Brief covers Millenium RAT amid the early-November 2023 disclosure window.
  • KrakenLabs documents the Malware-as-a-Service subscription model for the native C++ v4.x build, advertised at roughly $50/month and $90 for a lifetime license, lowering the barrier to entry for low-skilled operators.
  • KrakenLabs reports actor shinyenigma advertising Millenium RAT v4.1 on an English-speaking underground forum as a C++ Telegram-controlled RAT with stealer and keylogger features.
  • Q1 2026 surge: 39,730 new infections recorded — 63.8% of all documented compromises — marking peak deployment velocity.
  • ShinyEnigma launches renewed marketing operations for the native C++ Millenium RAT MaaS offering.
  • Group-IB's report tallies cumulative documented impact of 62,289 infected endpoints across 160+ countries, with native C++ v4.x removing the .NET runtime dependency to reduce footprint and evade .NET-focused detections.
  • Group-IB publishes 'anatomy of a Malware-as-a-Service operation', documenting the v4.x native C++ rewrite, 62,289 endpoints across 160+ countries, full IOC set (11 network IOCs, 40+ hashes), and pricing ($50 first month / $10 subsequent / $90 lifetime).

Sources cited for Millenium RAT v4.x

Threats related to Millenium RAT v4.x

Detection coverage for TL-2026-0942

As of 2026-06-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0942 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-0942

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats