ThreatBeaconXThreatBeaconXSubscribe
HighMalware · 7 min read

ne-rat C2 Infrastructure Analysis: Web Panel, Virtualizor Compromise, and Infrastructure Pivots

The ne-rat ecosystem uses web-based C2 infrastructure to manage compromised systems. This analysis examines the offline `web.ne-rat[.]xyz` C2 panel, associated infrastructure, the `widdow.jar` Java RAT, and infrastructure pivots identified during investigation of the August 2026 Virtualizor compromise. The report documents observed C2 domains, IP addresses, payload and persistence indicators, MITRE ATT&CK mappings, infrastructure relationships, and practical detection and threat-hunting recommendations for security teams.

Written by Battula Bhanu Prakash·Published Sep 3, 2026
ne-rat C2 Infrastructure Analysis: Web Panel, Virtualizor Compromise, and Infrastructure Pivots

The ne-rat ecosystem is associated with Remote Access Trojan (RAT) infrastructure designed to provide attackers with centralized control and management of compromised systems.

This analysis examines the web-based C2 management panel web.ne-rat[.]xyz, associated C2 infrastructure, payload delivery infrastructure, persistence mechanisms, indicators of compromise, and infrastructure relationships identified during the investigation of the August 2026 Virtualizor compromise.

The web panel is currently offline. However, historical infrastructure, forensic reporting, and related infrastructure provide useful intelligence for understanding the ne-rat ecosystem.

During the August 2026 Virtualizor incident, an unauthorized BGP route hijacking redirected traffic destined for part of the Softaculous/Virtualizor infrastructure to attacker-controlled infrastructure. A malicious Virtualizor update was subsequently delivered to a small number of affected installations.

The reported payload, widdow.jar, was downloaded from:

cdn[.]nerat[.]cc/installer/widdow.jar

The payload was subsequently executed from:

/usr/lib/jvm/.cache/jre-runtime.dat

Observed C2 communication from an affected host was reported to:

31.77.220[.]138:2025

with connect[.]ne-rat[.]xyz identified as the C2 resolution domain and web[.]ne-rat[.]xyz reported as the associated web-based management panel.

Key Highlights

  • ne-rat-associated web C2 panel: web.ne-rat[.]xyz

  • C2 resolution domain: connect.ne-rat[.]xyz

  • Observed C2 destination: 31.77.220[.]138:2025

  • Payload delivery infrastructure: cdn.nerat[.]cc

  • Reported Java RAT payload: widdow.jar

  • Reported payload path: /usr/lib/jvm/.cache/jre-runtime.dat

  • Reported SHA-256: b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46989bdc944a7870c7

  • Persistence service: java-jre-update.service

  • Unauthorized account: proxyuser

  • Multiple domains identified through infrastructure pivoting

  • Multiple MITRE ATT&CK techniques associated with the reported activity

What is ne-rat?

Available evidence describes ne-rat as a Remote Access Trojan ecosystem with centralized infrastructure for managing compromised hosts.

A typical RAT infrastructure consists of several components:

  • Web C2 Panel — operator-facing management interface

  • C2 Server — communicates with infected systems

  • Payload/CDN — delivers malware components

  • Victim Endpoint — compromised system running the RAT

In this investigation, web.ne-rat[.]xyz represents the reported web-based management interface, while connect.ne-rat[.]xyz was associated with C2 resolution.

The discovery of a web panel does not necessarily mean that the panel itself infects systems. Its primary purpose may be command execution, monitoring, task management, and administration of already-deployed RAT clients.

Why the C2 Web Panel Matters

Even when a C2 panel is offline, it can retain significant threat-intelligence value.

Web applications may expose:

  • JavaScript bundles

  • CSS files

  • API endpoints

  • WebSocket endpoints

  • Authentication paths

  • HTML comments

  • Framework information

  • Configuration references

  • Domain names

  • IP addresses

  • Version strings

  • Route names

  • Client-management functionality

JavaScript files can be particularly valuable because they may contain references to backend hosts, API routes, WebSocket connections, authentication endpoints, feature names, and hardcoded configuration.

Historical copies of JavaScript bundles may therefore preserve useful relationships after the original infrastructure has gone offline.

CSS artifacts can also help identify reused templates, UI frameworks, and relationships between apparently unrelated web applications.

Relationship to the August 2026 Virtualizor Incident

The ne-rat infrastructure became particularly relevant following the August 2026 Virtualizor incident.

According to the investigation described in the report, an unauthorized BGP announcement redirected traffic associated with the 162.55.80.0/24 address range.

The attack began at approximately 20:57 UTC on 28 August 2026, with normal routing restored at approximately 06:10 UTC on 30 August 2026.

Because certificate-validation traffic was also affected by the routing hijack, the attacker was able to obtain a technically valid TLS certificate for affected domains.

A malicious Virtualizor update package was subsequently delivered to a small number of installations that checked for updates while their traffic was diverted.

This demonstrates the security risks associated with trusting software-update infrastructure without strong cryptographic verification.

Reported Attack Chain

BGP Route Hijacking
↓
Traffic redirected to attacker infrastructure
↓
Virtualizor update check
↓
Malicious update/package delivered
↓
Malicious code executes with root privileges
↓
RAT downloaded
↓
widdow.jar executed
↓
Persistence established
↓
C2 communication
↓
ne-rat infrastructure
↓
Operator web panel

The Virtualizor investigation provides evidence for the BGP hijacking and malicious update delivery, while subsequent forensic reporting documented the ne-rat payload and related infrastructure.

Malware Payload

The reported payload was:

widdow.jar

Download Location

cdn[.]nerat[.]cc/installer/widdow.jar

Reported Execution Path

/usr/lib/jvm/.cache/jre-runtime.dat

Reported File Size

Approximately 13.5 MB

SHA-256

b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46989bdc944a7870c7

The hash should be used as a detection indicator where the underlying file can be collected and examined.

Persistence Mechanism

One of the strongest host-level indicators was the systemd service:

java-jre-update.service

The reported payload location was:

/usr/lib/jvm/.cache/jre-runtime.dat

The service was configured to execute the Java payload and provide repeated execution.

The naming may resemble legitimate Java runtime or update functionality, potentially allowing the malicious service to blend into normal system activity.

This behavior maps to:

T1543.002 — Create or Modify System Process: Systemd Service

Additional Access and Persistence Indicators

Forensic reporting also identified the following indicators.

Unauthorized Account

proxyuser

Reported SSH Source IP

193.32.127[.]248

SSH Key Fingerprint

SHA256:YQmy1hKF1h5cdJLxlZ5EScNoxe/UDWahjsWuQw2ERi8

Additional Marker Files

/usr/lib/jvm/.cache/.installed

/tmp/.vz_svc_done

The addition of an attacker-controlled SSH public key provides an independent persistence mechanism beyond the RAT.

This activity maps to:

T1098.004 — Account Manipulation: SSH Authorized Keys

C2 Infrastructure

IndicatorRoleConfidence
web.ne-rat[.]xyzWeb-based operator/C2 panelHigh
connect.ne-rat[.]xyzC2 resolution/domainHigh
31.77.220[.]138:2025Observed C2 destinationHigh
cdn.nerat[.]ccPayload delivery infrastructureHigh
widdow.jarRAT payloadHigh

The observed connection to 31.77.220[.]138:2025 disappeared after the malicious Java process was stopped, providing strong evidence that the destination was associated with the malware's communications.

Infrastructure Pivoting

Infrastructure pivoting allows analysts to move beyond a single domain and identify relationships between potentially connected infrastructure.

Useful pivoting sources include:

  • Passive DNS

  • WHOIS/RDAP

  • TLS certificates

  • Nameservers

  • IP addresses

  • Autonomous Systems

  • Hosting providers

  • Registration dates

  • Domain patterns

  • URL paths

  • HTTP headers

  • Favicon hashes

  • JavaScript references

  • Historical DNS records

  • Shared infrastructure

The investigation identified the following additional domains:

  • autolackierereiberlin[.]com

  • elssgmbh[.]com

  • hairfrbeauty[.]com

  • lesgarconsbarbiersop[.]com

  • monero-cash[.]com

  • monify-cash[.]com

  • monix-cash[.]com

  • timiderbarbershop[.]com

  • web-test[.]ne-rat[.]xyz

These domains should be treated as pivoted or related infrastructure requiring additional validation, rather than automatically being classified as confirmed malicious C2 endpoints.

Infrastructure Confidence

A domain discovered through infrastructure pivoting should not automatically be classified as malicious.

Additional corroborating evidence should include:

  • Malware communication

  • Passive DNS relationships

  • Shared TLS certificates

  • Shared hosting infrastructure

  • Identical web-panel artifacts

  • Malware configuration references

  • Historical resolution to known C2 infrastructure

  • Independent threat-intelligence or vendor confirmation

This distinction helps reduce false positives and prevents unsupported infrastructure attribution.

MITRE ATT&CK Mapping

MITRE IDTechniqueEvidence
T1195.002Compromise Software Supply ChainMalicious Virtualizor update delivered during infrastructure hijacking
T1105Ingress Tool Transferwiddow.jar downloaded from attacker-controlled infrastructure
T1543.002Create or Modify System Process: Systemd Servicejava-jre-update.service used for persistence
T1098.004Account Manipulation: SSH Authorized KeysAttacker-controlled SSH key added
T1021.004Remote Services: SSHSSH access observed from reported attacker infrastructure
T1059.004Unix ShellPotentially applicable where supporting command-execution evidence exists

The strongest initial-access mapping is T1195.002 — Compromise Software Supply Chain, based on the reported malicious update delivery during the infrastructure hijacking event.

Techniques Not Claimed Without Evidence

The following techniques should not automatically be attributed to this activity without additional supporting evidence:

  • T1071.001 — Web Protocols

  • T1041 — Exfiltration Over C2 Channel

  • T1567 — Exfiltration Over Web Service

  • T1486 — Data Encrypted for Impact

  • T1059.001 — PowerShell

  • T1566 — Phishing

  • T1078 — Valid Accounts

  • T1027 — Obfuscated/Compressed Files

The presence of a C2 server does not by itself prove that data exfiltration occurred.

A professional threat-intelligence assessment should distinguish between:

Observed → Corroborated → Assessed → Unconfirmed

Indicators of Compromise

Network IOCs

TypeIndicatorStatus
C2 IP31.77.220[.]138Confirmed/Observed
C2 Port2025Observed
C2 Domainconnect.ne-rat[.]xyzStrong association
Web Panelweb.ne-rat[.]xyzStrong association
Payload CDNcdn.nerat[.]ccStrong association
SSH Source193.32.127[.]248Provider-reported

File IOCs

  • widdow.jar

  • /usr/lib/jvm/.cache/jre-runtime.dat

  • /etc/systemd/system/java-jre-update.service

  • /usr/lib/jvm/.cache/.installed

  • /tmp/.vz_svc_done

  • /tmp/widdow.jar

Account Indicators

  • Unauthorized account: proxyuser

  • SSH key fingerprint: SHA256:YQmy1hKF1h5cdJLxlZ5EScNoxe/UDWahjsWuQw2ERi8

File Hash

SHA-256:

b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46989bdc944a7870c7

Detection and Threat Hunting

Security teams should hunt for combinations of these indicators rather than relying on a single IOC.

Process Hunting

Investigate Java processes running from unusual locations, particularly references to:

jre-runtime.dat

widdow.jar

File-System Hunting

Search for:

/usr/lib/jvm/.cache/jre-runtime.dat

/usr/lib/jvm/.cache/.installed

/tmp/widdow.jar

/tmp/.vz_svc_done

Systemd Hunting

Look for:

java-jre-update.service

Unexpected .service files under system-level systemd directories should be investigated.

Network Hunting

Search DNS and network telemetry for:

connect.ne-rat[.]xyz

cdn.nerat[.]cc

web.ne-rat[.]xyz

31.77.220[.]138

Particular attention should be given to:

31.77.220[.]138:2025

SSH Hunting

Review:

  • /root/.ssh/authorized_keys

  • Newly created users

  • Successful SSH logins

  • Unusual source IP addresses

  • Password authentication events

  • Unexpected root logins

Incident Response Recommendations

If a confirmed IOC is discovered, security teams should consider the following steps.

1. Isolate

Restrict network access to the affected host while preserving forensic evidence.

2. Preserve Evidence

Before deleting suspicious files:

  • Capture memory where possible

  • Collect disk evidence

  • Preserve system logs

  • Preserve authentication logs

  • Hash suspicious files

  • Record timestamps

3. Investigate Persistence

Review:

  • systemd services

  • cron jobs

  • SSH keys

  • User accounts

  • Startup scripts

  • Scheduled tasks

4. Rotate Credentials

Where compromise is confirmed, rotate:

  • API keys

  • SSH keys

  • Administrative passwords

  • Service credentials

5. Investigate Lateral Activity

Because the reported compromise involved root-level access, investigation should extend beyond the RAT.

Review:

  • SSH logs

  • Shell history

  • Authentication logs

  • Network connections

  • Newly created accounts

  • New services

  • Modified configuration files

  • Access to customer workloads

6. Rebuild Where Appropriate

A system that experienced confirmed root-level compromise should be considered highly untrusted. Depending on organizational incident-response procedures, rebuilding from known-good media may be preferable to attempting to clean the affected system.

Key Takeaways

  • An offline C2 panel can retain significant threat-intelligence value.

  • JavaScript, CSS, DNS, certificates, and historical infrastructure can reveal relationships between C2 components.

  • The reported Virtualizor incident demonstrates the risks associated with compromised software-update infrastructure.

  • Persistence mechanisms such as systemd services and SSH authorized keys should be investigated independently of the RAT.

  • Pivoted domains should not automatically be classified as confirmed malicious infrastructure.

  • SOC teams should correlate process, filesystem, systemd, authentication, DNS, and network telemetry.

  • Threat-intelligence reporting should clearly distinguish observed evidence from assessment and unconfirmed activity.

Conclusion

The investigation into web.ne-rat[.]xyz demonstrates how threat intelligence can extend beyond the identification of a single malicious domain.

Although the web panel is currently offline, the associated C2 domain, IP address, payload delivery infrastructure, Java RAT payload, persistence mechanisms, authentication artifacts, and related infrastructure provide multiple avenues for detection and further investigation.

The August 2026 Virtualizor incident also highlights the broader risks created when attackers compromise trusted software-delivery infrastructure.

For defenders, the key lesson is:

An IOC is only the starting point. Mapping relationships between infrastructure, malware, persistence, authentication, and observed activity provides a stronger basis for threat detection and incident response.

Indicators of Compromise

TypeValueNotes
IPv431.77.220[.]138Observed C2 destination
IPv4193.32.127[.]248Reported SSH source
Domainconnect.ne-rat[.]xyzStrong C2 association
Domainweb.ne-rat[.]xyzReported C2 web panel
Domaincdn.nerat[.]ccReported payload delivery infrastructure
SHA-256b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46989bdc944a7870c7Reported widdow.jar hash

MITRE ATT&CK Mapping

T1195.002 — Compromise Software Supply ChainT1105 — Ingress Tool TransferT1543.002 — Create or Modify System Process: Systemd ServiceT1098.004 — Account Manipulation: SSH Authorized KeysT1021.004 — Remote Services: SSH