FILEMembers
FILE

Cracked SQLi Dumper Tool Doubles as BitRAT Delivery Vehicle

A pirated copy of the SQLi Dumper v8.5 pentesting tool is being used to plant the BitRAT trojan on self-selecting victims who go looking for free security software. Shared packing and anti-analysis checks tie two lure files together, while a single isolated Russian-hosted IP and an unrelated third payload round out a thin but suggestive indicator set.

Aug 18, 2026, 14:51 (UTC+9)Last seenAug 18, 2026Severity62ByCTX TeamActorBlueBottleOpera1erIOC6MITRE23RegionsIT

A pirated copy of a well-known penetration-testing utility is being used as bait to plant a commodity remote-access trojan on victim machines, according to indicators CTX Team has reviewed. Two Win32 executables in this cluster present themselves as a "cracked" release of SQLi Dumper v8.5, a SQL-injection scanning tool popular with penetration testers and opportunistic attackers alike, while sharing the same packing signature and a matching set of anti-analysis checks.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence