The ne-rat ecosystem is associated with Remote Access Trojan (RAT) infrastructure designed to provide attackers with centralized control and management of compromised systems.
This analysis examines the web-based C2 management panel web.ne-rat[.]xyz, associated C2 infrastructure, payload delivery infrastructure, persistence mechanisms, indicators of compromise, and infrastructure relationships identified during the investigation of the August 2026 Virtualizor compromise.
The web panel is currently offline. However, historical infrastructure, forensic reporting, and related infrastructure provide useful intelligence for understanding the ne-rat ecosystem.
During the August 2026 Virtualizor incident, an unauthorized BGP route hijacking redirected traffic destined for part of the Softaculous/Virtualizor infrastructure to attacker-controlled infrastructure. A malicious Virtualizor update was subsequently delivered to a small number of affected installations.
The reported payload, widdow.jar, was downloaded from:
cdn[.]nerat[.]cc/installer/widdow.jar
The payload was subsequently executed from:
/usr/lib/jvm/.cache/jre-runtime.dat
Observed C2 communication from an affected host was reported to:
31.77.220[.]138:2025
with connect[.]ne-rat[.]xyz identified as the C2 resolution domain and web[.]ne-rat[.]xyz reported as the associated web-based management panel.
Key Highlights
ne-rat-associated web C2 panel:
web.ne-rat[.]xyzC2 resolution domain:
connect.ne-rat[.]xyzObserved C2 destination:
31.77.220[.]138:2025Payload delivery infrastructure:
cdn.nerat[.]ccReported Java RAT payload:
widdow.jarReported payload path:
/usr/lib/jvm/.cache/jre-runtime.datReported SHA-256:
b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46989bdc944a7870c7Persistence service:
java-jre-update.serviceUnauthorized account:
proxyuserMultiple domains identified through infrastructure pivoting
Multiple MITRE ATT&CK techniques associated with the reported activity
What is ne-rat?
Available evidence describes ne-rat as a Remote Access Trojan ecosystem with centralized infrastructure for managing compromised hosts.
A typical RAT infrastructure consists of several components:
Web C2 Panel — operator-facing management interface
C2 Server — communicates with infected systems
Payload/CDN — delivers malware components
Victim Endpoint — compromised system running the RAT
In this investigation, web.ne-rat[.]xyz represents the reported web-based management interface, while connect.ne-rat[.]xyz was associated with C2 resolution.
The discovery of a web panel does not necessarily mean that the panel itself infects systems. Its primary purpose may be command execution, monitoring, task management, and administration of already-deployed RAT clients.
Why the C2 Web Panel Matters
Even when a C2 panel is offline, it can retain significant threat-intelligence value.
Web applications may expose:
JavaScript bundles
CSS files
API endpoints
WebSocket endpoints
Authentication paths
HTML comments
Framework information
Configuration references
Domain names
IP addresses
Version strings
Route names
Client-management functionality
JavaScript files can be particularly valuable because they may contain references to backend hosts, API routes, WebSocket connections, authentication endpoints, feature names, and hardcoded configuration.
Historical copies of JavaScript bundles may therefore preserve useful relationships after the original infrastructure has gone offline.
CSS artifacts can also help identify reused templates, UI frameworks, and relationships between apparently unrelated web applications.
Relationship to the August 2026 Virtualizor Incident
The ne-rat infrastructure became particularly relevant following the August 2026 Virtualizor incident.
According to the investigation described in the report, an unauthorized BGP announcement redirected traffic associated with the 162.55.80.0/24 address range.
The attack began at approximately 20:57 UTC on 28 August 2026, with normal routing restored at approximately 06:10 UTC on 30 August 2026.
Because certificate-validation traffic was also affected by the routing hijack, the attacker was able to obtain a technically valid TLS certificate for affected domains.
A malicious Virtualizor update package was subsequently delivered to a small number of installations that checked for updates while their traffic was diverted.
This demonstrates the security risks associated with trusting software-update infrastructure without strong cryptographic verification.
Reported Attack Chain
BGP Route Hijacking
↓
Traffic redirected to attacker infrastructure
↓
Virtualizor update check
↓
Malicious update/package delivered
↓
Malicious code executes with root privileges
↓
RAT downloaded
↓
widdow.jar executed
↓
Persistence established
↓
C2 communication
↓
ne-rat infrastructure
↓
Operator web panel
The Virtualizor investigation provides evidence for the BGP hijacking and malicious update delivery, while subsequent forensic reporting documented the ne-rat payload and related infrastructure.
Malware Payload
The reported payload was:
widdow.jar
Download Location
cdn[.]nerat[.]cc/installer/widdow.jar
Reported Execution Path
/usr/lib/jvm/.cache/jre-runtime.dat
Reported File Size
Approximately 13.5 MB
SHA-256
b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46989bdc944a7870c7
The hash should be used as a detection indicator where the underlying file can be collected and examined.
Persistence Mechanism
One of the strongest host-level indicators was the systemd service:
java-jre-update.service
The reported payload location was:
/usr/lib/jvm/.cache/jre-runtime.dat
The service was configured to execute the Java payload and provide repeated execution.
The naming may resemble legitimate Java runtime or update functionality, potentially allowing the malicious service to blend into normal system activity.
This behavior maps to:
T1543.002 — Create or Modify System Process: Systemd Service
Additional Access and Persistence Indicators
Forensic reporting also identified the following indicators.
Unauthorized Account
proxyuser
Reported SSH Source IP
193.32.127[.]248
SSH Key Fingerprint
SHA256:YQmy1hKF1h5cdJLxlZ5EScNoxe/UDWahjsWuQw2ERi8
Additional Marker Files
/usr/lib/jvm/.cache/.installed
/tmp/.vz_svc_done
The addition of an attacker-controlled SSH public key provides an independent persistence mechanism beyond the RAT.
This activity maps to:
T1098.004 — Account Manipulation: SSH Authorized Keys
C2 Infrastructure
| Indicator | Role | Confidence |
|---|---|---|
web.ne-rat[.]xyz | Web-based operator/C2 panel | High |
connect.ne-rat[.]xyz | C2 resolution/domain | High |
31.77.220[.]138:2025 | Observed C2 destination | High |
cdn.nerat[.]cc | Payload delivery infrastructure | High |
widdow.jar | RAT payload | High |
The observed connection to 31.77.220[.]138:2025 disappeared after the malicious Java process was stopped, providing strong evidence that the destination was associated with the malware's communications.
Infrastructure Pivoting
Infrastructure pivoting allows analysts to move beyond a single domain and identify relationships between potentially connected infrastructure.
Useful pivoting sources include:
Passive DNS
WHOIS/RDAP
TLS certificates
Nameservers
IP addresses
Autonomous Systems
Hosting providers
Registration dates
Domain patterns
URL paths
HTTP headers
Favicon hashes
JavaScript references
Historical DNS records
Shared infrastructure
The investigation identified the following additional domains:
autolackierereiberlin[.]comelssgmbh[.]comhairfrbeauty[.]comlesgarconsbarbiersop[.]commonero-cash[.]commonify-cash[.]commonix-cash[.]comtimiderbarbershop[.]comweb-test[.]ne-rat[.]xyz
These domains should be treated as pivoted or related infrastructure requiring additional validation, rather than automatically being classified as confirmed malicious C2 endpoints.
Infrastructure Confidence
A domain discovered through infrastructure pivoting should not automatically be classified as malicious.
Additional corroborating evidence should include:
Malware communication
Passive DNS relationships
Shared TLS certificates
Shared hosting infrastructure
Identical web-panel artifacts
Malware configuration references
Historical resolution to known C2 infrastructure
Independent threat-intelligence or vendor confirmation
This distinction helps reduce false positives and prevents unsupported infrastructure attribution.
MITRE ATT&CK Mapping
| MITRE ID | Technique | Evidence |
|---|---|---|
| T1195.002 | Compromise Software Supply Chain | Malicious Virtualizor update delivered during infrastructure hijacking |
| T1105 | Ingress Tool Transfer | widdow.jar downloaded from attacker-controlled infrastructure |
| T1543.002 | Create or Modify System Process: Systemd Service | java-jre-update.service used for persistence |
| T1098.004 | Account Manipulation: SSH Authorized Keys | Attacker-controlled SSH key added |
| T1021.004 | Remote Services: SSH | SSH access observed from reported attacker infrastructure |
| T1059.004 | Unix Shell | Potentially applicable where supporting command-execution evidence exists |
The strongest initial-access mapping is T1195.002 — Compromise Software Supply Chain, based on the reported malicious update delivery during the infrastructure hijacking event.
Techniques Not Claimed Without Evidence
The following techniques should not automatically be attributed to this activity without additional supporting evidence:
T1071.001 — Web Protocols
T1041 — Exfiltration Over C2 Channel
T1567 — Exfiltration Over Web Service
T1486 — Data Encrypted for Impact
T1059.001 — PowerShell
T1566 — Phishing
T1078 — Valid Accounts
T1027 — Obfuscated/Compressed Files
The presence of a C2 server does not by itself prove that data exfiltration occurred.
A professional threat-intelligence assessment should distinguish between:
Observed → Corroborated → Assessed → Unconfirmed
Indicators of Compromise
Network IOCs
| Type | Indicator | Status |
|---|---|---|
| C2 IP | 31.77.220[.]138 | Confirmed/Observed |
| C2 Port | 2025 | Observed |
| C2 Domain | connect.ne-rat[.]xyz | Strong association |
| Web Panel | web.ne-rat[.]xyz | Strong association |
| Payload CDN | cdn.nerat[.]cc | Strong association |
| SSH Source | 193.32.127[.]248 | Provider-reported |
File IOCs
widdow.jar/usr/lib/jvm/.cache/jre-runtime.dat/etc/systemd/system/java-jre-update.service/usr/lib/jvm/.cache/.installed/tmp/.vz_svc_done/tmp/widdow.jar
Account Indicators
Unauthorized account:
proxyuserSSH key fingerprint:
SHA256:YQmy1hKF1h5cdJLxlZ5EScNoxe/UDWahjsWuQw2ERi8
File Hash
SHA-256:
b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46989bdc944a7870c7
Detection and Threat Hunting
Security teams should hunt for combinations of these indicators rather than relying on a single IOC.
Process Hunting
Investigate Java processes running from unusual locations, particularly references to:
jre-runtime.dat
widdow.jar
File-System Hunting
Search for:
/usr/lib/jvm/.cache/jre-runtime.dat
/usr/lib/jvm/.cache/.installed
/tmp/widdow.jar
/tmp/.vz_svc_done
Systemd Hunting
Look for:
java-jre-update.service
Unexpected .service files under system-level systemd directories should be investigated.
Network Hunting
Search DNS and network telemetry for:
connect.ne-rat[.]xyz
cdn.nerat[.]cc
web.ne-rat[.]xyz
31.77.220[.]138
Particular attention should be given to:
31.77.220[.]138:2025
SSH Hunting
Review:
/root/.ssh/authorized_keysNewly created users
Successful SSH logins
Unusual source IP addresses
Password authentication events
Unexpected root logins
Incident Response Recommendations
If a confirmed IOC is discovered, security teams should consider the following steps.
1. Isolate
Restrict network access to the affected host while preserving forensic evidence.
2. Preserve Evidence
Before deleting suspicious files:
Capture memory where possible
Collect disk evidence
Preserve system logs
Preserve authentication logs
Hash suspicious files
Record timestamps
3. Investigate Persistence
Review:
systemd services
cron jobs
SSH keys
User accounts
Startup scripts
Scheduled tasks
4. Rotate Credentials
Where compromise is confirmed, rotate:
API keys
SSH keys
Administrative passwords
Service credentials
5. Investigate Lateral Activity
Because the reported compromise involved root-level access, investigation should extend beyond the RAT.
Review:
SSH logs
Shell history
Authentication logs
Network connections
Newly created accounts
New services
Modified configuration files
Access to customer workloads
6. Rebuild Where Appropriate
A system that experienced confirmed root-level compromise should be considered highly untrusted. Depending on organizational incident-response procedures, rebuilding from known-good media may be preferable to attempting to clean the affected system.
Key Takeaways
An offline C2 panel can retain significant threat-intelligence value.
JavaScript, CSS, DNS, certificates, and historical infrastructure can reveal relationships between C2 components.
The reported Virtualizor incident demonstrates the risks associated with compromised software-update infrastructure.
Persistence mechanisms such as systemd services and SSH authorized keys should be investigated independently of the RAT.
Pivoted domains should not automatically be classified as confirmed malicious infrastructure.
SOC teams should correlate process, filesystem, systemd, authentication, DNS, and network telemetry.
Threat-intelligence reporting should clearly distinguish observed evidence from assessment and unconfirmed activity.
Conclusion
The investigation into web.ne-rat[.]xyz demonstrates how threat intelligence can extend beyond the identification of a single malicious domain.
Although the web panel is currently offline, the associated C2 domain, IP address, payload delivery infrastructure, Java RAT payload, persistence mechanisms, authentication artifacts, and related infrastructure provide multiple avenues for detection and further investigation.
The August 2026 Virtualizor incident also highlights the broader risks created when attackers compromise trusted software-delivery infrastructure.
For defenders, the key lesson is:
An IOC is only the starting point. Mapping relationships between infrastructure, malware, persistence, authentication, and observed activity provides a stronger basis for threat detection and incident response.