Millenium RAT v4.x — Native C++ Telegram-Controlled Remote Access Trojan & Infostealer Sold as Malware-as-a-Service (ShinyEnigma)
Millenium RAT v4.x (TL-2026-0942), also tracked as Millenium RAT, is a critical-severity malware campaign, first published 2026-06-25. It is attributed to ShinyEnigma with medium confidence, affects Microsoft Windows, maps to 37 MITRE ATT&CK techniques (T1005, T1012, T1027), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-0942
- Threat ID
- TL-2026-0942
- Also known as
- Millenium RAT, Millennium RAT, Millenium Stealer
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-06-25
- Last reviewed
- 2026-06-25
- Attribution
- ShinyEnigma
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- consumer, gaming, cryptocurrency, technology, financial
- Target regions
- Global, Russia, North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Millenium RAT v4.x
Malware and tooling: Telegram Bot API (getUpdates polling)
Millenium RAT is a Windows Remote Access Trojan and infostealer distributed as Malware-as-a-Service by the actor 'ShinyEnigma'. Group-IB reports version 4.x was rewritten from .NET to a native C++ application, removing the .NET runtime dependency while retaining serverless Telegram Bot API command-and-control. The operation is tied to 62,289 compromised endpoints across 160+ countries, with 39,730 infections (63.8%) in Q1 2026 alone.
How Millenium RAT v4.x works
Millenium RAT is a commodity Windows Remote Access Trojan and credential/cryptocurrency stealer marketed as a low-cost Malware-as-a-Service (MaaS) by an actor using the handle 'ShinyEnigma' (also 'shinyenigma'), with active exploitation attributed by Group-IB to a cluster tracked as 'Y2K Operators'. The malware first surfaced in November 2023 (CYFIRMA, version 2.4), where it was assessed as a derivative of the open-source ToxicEye Telegram RAT, sharing structure, modules, namespaces and function names. By June 2026 the project had been rewritten: Group-IB's 25 June 2026 analysis documents version 4.x as a native C++ application compiled to a standalone PE, eliminating the .NET Framework runtime dependency present in earlier builds and reducing detection surface.
C2 is serverless: rather than operating dedicated infrastructure, each build communicates with the Telegram Bot API over HTTPS using the getUpdates polling method, with an embedded bot token and chat id. Operator commands are issued through the Telegram chat in the form /[4-digit-botid]*command*parameter1*parameter2, exposing 50+ implemented functions. Configuration is stored in an embedded PE RCDATA resource as a Base64-encoded, custom-XOR-encrypted blob containing fields including token, id, name (used simultaneously as the mutex identifier and HKCU registry value name), start_delay, query_delay, keylog_filename, install_foldername, and boolean feature flags persist, keylogger, elevate, auto_steal and detect_sandbox.
Capabilities span the full RAT/stealer feature set: extraction of browser-stored passwords, cookies and history; theft of Telegram and Discord session/token data; cryptocurrency wallet and browser-extension wallet recovery ('walletRecovery'); keylogging; screenshot capture; 15-second audio recording; webcam access; and host reconnaissance (administrator-privilege check, CPU/GPU, total RAM, Hardware ID, Windows version, architecture, antivirus status, installed software). Destructive/impact functions include file encryption and decryption, system shutdown and restart, BSOD triggering, and display rotation. Persistence is achieved via an HKCU\Software\Microsoft\Windows\CurrentVersion\Run autorun entry and installation of the executable into a %APPDATA% subfolder, with an HKCU\Software\[name] semaphore key tracking first-versus-subsequent execution. Anti-analysis features include sandbox and AV/EDR detection, Windows Defender preference modification, configuration obfuscation, and a self-uninstall routine.
Distribution relies on social-engineering lures hosted on attacker-controlled domains and file hosts: fraud utilities (gift-card/crypto generators), 'hacking toolkits' (OSINT, WiFi cracking), software cracks/KYC-bypass tools, Roblox-themed game cheats, and trojanized builders of other RATs (XWorm, AsyncRAT, njRAT). Payloads are commonly delivered via LNK shortcuts disguised as PDFs, PowerShell downloaders and VBS intermediaries that stage a decoy document while silently executing the RAT. Exfiltration is performed over the Telegram Bot API and the Gofile cloud-storage service, with staged data Base64-encoded. The developer advertised the project on a marketing site (milleniumrat.online), Dread forum posts, and code-hosting repositories on GitHub, GitLab and Gitea; pricing for v4.x is $50 for the first month, $10 for subsequent months, or a one-time $90 lifetime purchase (down-market from the $30 lifetime price of v2.4).
MITRE ATT&CK techniques used in TL-2026-0942
Collection
T1005 Data from Local System; T1056 Input Capture; T1074 Data Staged; T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture; T1560 Archive Collected Data
Discovery
T1012 Query Registry; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1217 Browser Information Discovery; T1518 Software Discovery; T1614 System Location Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution; T1674 Input Injection
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1529 System Shutdown/Reboot
Credential Access
T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Persistence
T1547 Boot or Logon Autostart Execution
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
defense-impairment
Affected products and versions in Millenium RAT v4.x
- Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11; Windows Server (user endpoints)
Remediation for Millenium RAT v4.x
Immediate actions
- Block all listed C2/distribution domains and IPs (blackhatusa.com, milleniumrat.online, 75877.mcdir.me, modedapk.net, thesnapchatmodapk.com, kuttabilla.top, 158.94.208.168, 62.60.226.97, 130.12.180.43) at perimeter and DNS resolvers
- Alert on outbound HTTPS to api.telegram.org/bot*/getUpdates from non-sanctioned hosts and on traffic to gofile.io upload endpoints
- Hunt for HKCU\Software\Microsoft\Windows\CurrentVersion\Run autorun values pointing into %APPDATA% subfolders and quarantine matching SHA256 samples
- Block execution of the listed lure filenames and masquerading binaries (svchost.exe, MsEdgeUpdate.exe, Microsoft Antivirus.exe, MSAV.exe, rcsdriver.exe) from user-writable paths
Workarounds
- Disable Windows Script Host (wscript/cscript) where not required to break VBS staging
- Enable Defender tamper protection to resist preference modification
Longer-term hardening
- Deploy EDR with behavioral detection for LNK-to-PowerShell-to-VBS execution chains and credential-store/clipboard access
- Enforce application allow-listing (WDAC/AppLocker) to prevent execution of unsigned binaries from %APPDATA% and Downloads
- User awareness training targeting cracked-software, game-cheat and 'hacking tool' lures
- Restrict and monitor Telegram API egress; treat unexpected api.telegram.org traffic as suspicious
Timeline of Millenium RAT v4.x
- CYFIRMA's first public report documents Millenium RAT version 2.4 as a .NET-based commodity infostealer/RAT advertised on underground forums, establishing the malware family's pre-C++ lineage.
- CYFIRMA publishes first public report on Millenium RAT (version 2.4), assessing it as a derivative of the open-source ToxicEye Telegram RAT; advertised at $30 lifetime.
- Deepwatch Cyber Intel Brief covers Millenium RAT amid the early-November 2023 disclosure window.
- KrakenLabs documents the Malware-as-a-Service subscription model for the native C++ v4.x build, advertised at roughly $50/month and $90 for a lifetime license, lowering the barrier to entry for low-skilled operators.
- KrakenLabs reports actor shinyenigma advertising Millenium RAT v4.1 on an English-speaking underground forum as a C++ Telegram-controlled RAT with stealer and keylogger features.
- Q1 2026 surge: 39,730 new infections recorded — 63.8% of all documented compromises — marking peak deployment velocity.
- ShinyEnigma launches renewed marketing operations for the native C++ Millenium RAT MaaS offering.
- Group-IB's report tallies cumulative documented impact of 62,289 infected endpoints across 160+ countries, with native C++ v4.x removing the .NET runtime dependency to reduce footprint and evade .NET-focused detections.
- Group-IB publishes 'anatomy of a Malware-as-a-Service operation', documenting the v4.x native C++ rewrite, 62,289 endpoints across 160+ countries, full IOC set (11 network IOCs, 40+ hashes), and pricing ($50 first month / $10 subsequent / $90 lifetime).
Sources cited for Millenium RAT v4.x
- Millenium RAT: anatomy of a Malware-as-a-Service operation
- Unveiling a New Threat: The Millenium RAT
- BrinzTech Technical Advisory: Telegram C2 Infiltration Vectors and Crypto-Bound Decryption — The Millenium RAT Commercialization Cycle
- KrakenLabs: shinyenigma selling Millenium RAT v4.1 (C++ Telegram RAT + stealer)
- GitHub repository — Shinyenigma-official/Millenium-RAT
- Deepwatch Cyber Intel Brief: November 02-08, 2023 (Millenium RAT)
- CloudSEK / SC Media: XWorm RAT builder leveraged for widespread device compromise
Threats related to Millenium RAT v4.x
- Millenium RAT v4: C++ Rewrite Fuels Y2K Operators' MaaS Campaign (62,289 Devices, 160+ Countries)
- NanoCore RAT VBScript Loader Using Chr()/Math/Flow-Control Obfuscation to Evade Static Detection (CyberChef Analysis)
- WeedHack MaaS Campaign: Minecraft Fake Mod Loader with RSA-Signed Blockchain C2 (LoaderClient)
- Agent Tesla .NET Remote Access Trojan — Credential and Data Theft via Keylogging and MaaS Operations
- Remcos RAT Delivered via Steganographic Multi-Stage Loader in 'GST Debit Note' India-Targeted Phishing Campaign
- PureCrypter — C# Malware-as-a-Service Loader Distributing 10+ Malware Families
Detection coverage for TL-2026-0942
As of 2026-06-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0942 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0942
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.