Millenium RAT v4.x — Native C++ Telegram-Controlled Remote Access Trojan & Infostealer Sold as Malware-as-a-Service (ShinyEnigma) — Threadlinqs Intelligence
As of 2026-06-25, Millenium RAT v4.x — Native C++ Telegram-Controlled Remote Access Trojan & Infostealer Sold as Malware-as-a-Service (ShinyEnigma) is a critical-severity malware threat attributed to ShinyEnigma, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0942 · Severity: CRITICAL · Status: ACTIVE · Category: MALWARE
Attribution: ShinyEnigma · FINANCIAL
Millenium RAT is a Windows Remote Access Trojan and infostealer distributed as Malware-as-a-Service by the actor 'ShinyEnigma'. Group-IB reports version 4.x was rewritten from .NET to a native C++
Millenium RAT is a commodity Windows Remote Access Trojan and credential/cryptocurrency stealer marketed as a low-cost Malware-as-a-Service (MaaS) by an actor using the handle 'ShinyEnigma' (also 'shinyenigma'), with active exploitation attributed by Group-IB to a cluster tracked as 'Y2K Operators'. The malware first surfaced in November 2023 (CYFIRMA, version 2.4), where it was assessed as a derivative of the open-source ToxicEye Telegram RAT, sharing structure, modules, namespaces and function names. By June 2026 the project had been rewritten: Group-IB's 25 June 2026 analysis documents version 4.x as a native C++ application compiled to a standalone PE, eliminating the .NET Framework runtime dependency present in earlier builds and reducing detection surface.
C2 is serverless: rather than operating dedicated infrastructure, each build communicates with the Telegram Bot API over HTTPS using the getUpdates polling method, with an embedded bot token and chat id. Operator commands are issued through the Telegram chat in the form /[4-digit-botid]*command*parameter1*parameter2, exposing 50+ implemented functions. Configuration is stored in an embedded PE RCDATA resource as a Base64-encoded, custom-XOR-encrypted blob containing fields including token, id, name (used simultaneously as the mutex identifier and HKCU registry value name), start_delay, query_delay, keylog_filename, install_foldername, and boolean feature flags persist, keylogger, elevate, auto_steal and detect_sandbox.
Capabilities span the full RAT/stealer feature set: extraction of browser-stored passwords, cookies and history; theft of Telegram and Discord session/token data; cryptocurrency wallet and browser-extension wallet recovery ('walletRecovery'); keylogging; screenshot capture; 15-second audio recording; webcam access; and host reconnaissance (administrator-privilege check, CPU/GPU, total RAM, Hardware ID, Windows version, architecture, antivirus status, installed software). Destructive/impact functions include file encryption and decryption, system shutdown and restart, BSOD triggering, and display rotation. Persistence is achieved via an HKCU\Software\Microsoft\Windows\CurrentVersion\Run autorun entry and installation of the executable into a %APPDATA% subfolder, with an HKCU\Software\[name] semaphore key tracking first-versus-subsequent execution. Anti-analysis features include sandbox and AV/EDR detection, Windows Defender preference modification, configuration obfuscation, and a self-uninstall routine.
Distribution relies on social-engineering lures hosted on attacker-controlled domains and file hosts: fraud utilities (gift-card/crypto generators), 'hacking toolkits' (OSINT, WiFi cracking), software cracks/KYC-bypass tools, Roblox-themed game cheats, and trojanized builders of other RATs (XWorm, AsyncRAT, njRAT). Payloads are commonly delivered via LNK shortcuts disguised as PDFs, PowerShell downloaders and VBS intermediaries that stage a decoy document while silently executing the RAT. Exfiltration is performed over the Telegram Bot API and the Gofile cloud-storage service, with staged data Base64-encoded. The developer advertised the project on a marketing site (milleniumrat.online), Dread forum posts, and code-hosting repositories on GitHub, GitLab and Gitea; pricing for v4.x is $50 for the first month, $10 for subsequent months, or a one-time $90 lifetime purchase (down-market from the $30 lifetime price of v2.4).
Target sectors: consumer, gaming, cryptocurrency, technology, financial
Target regions: Global, Russia, North America, Europe, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, CRITICAL, threat intelligence, cybersecurity, T1059, T1059, T1674, T1106, T1204, T1547, T1548, T1140, T1562, T1070