Threat intelligence feed

njRAT IOC Feed

njRAT (Bladabindi) is a .NET remote access trojan. PrecisionSec's curated njRAT feed tracks active C2 and distribution infrastructure in real time.

15-day free trial · no credit card · reply within one business day

Drops straight into the tools your SOC already runs

What is njRAT?

njRAT (also known as Bladabindi) is a .NET remote access trojan that gives an attacker full control of an infected host, including keylogging, credential theft, webcam and microphone capture, and file transfer. It spreads through phishing attachments and infected USB drives, and remains common in commodity campaigns worldwide.

Why track it with PrecisionSec

  • Full remote control of the host. njRAT hands attackers keystrokes, credentials and live webcam and microphone access, an early foothold worth blocking fast.
  • Cut commodity-malware noise. High-confidence classification lets your SOC filter mass-distributed crimeware and focus on targeted, hands-on threats.
  • Built for your stack. Delivered via STIX/TAXII, MISP, CSV and REST API.

njRAT C2 and distribution IOCs are included in every PrecisionSec intelligence subscription.

Recent njRAT IOCs

Live njRAT command & control (C2) indicators, pulled straight from our threat feed and refreshed as fast as every minute. For full coverage and API delivery, sign up for a free trial.

Live feedUpdated 41s ago
First seenIndicatorTypeConfidence
3msecure-update-cdn[.]netC2 domainHigh
9m91.213.50[.]114C2 IPHigh
15mapi-telemetry-sync[.]com/loadPayload URLHigh
22mb7e2f48c…3d90afSHA256 HashMedium
38mnode-relay-7f1c[.]orgC2 domainHigh
Live njRAT indicators, surfaced and verified the moment they appear. Shown defanged — the ↗ icon opens the full record in Indicator Search, free. Raw, real-time data via the REST API or a free trial.

Ready to see all of our data?

Start your 15-day free trial and get the full njRAT feed, plus every other malware and C2 feed.

Request a 15-day trial