Cybercrime DB

RAT Malware Operators Charged in Criminal Cases

Subscription malware businesses leave digital paper trails that federal agents know how to follow.

Contributing Editor · · 8 min read · Updated
Cover illustration for “RAT Malware Operators Charged in Criminal Cases”
malware operators and developers · August 23, 2026 · 8 min read · 1,843 words

RAT stands for Remote Access Trojan. It's malware that hands an attacker full control of your computer: files, keystrokes, webcam, credentials, the works. This piece is about the criminal cases against the people who build and sell these tools, and what those cases reveal, which is that RAT operators build the evidence that convicts them into the product itself.

That's a design flaw baked into the business model.

RATs were the second most common malware type sold on criminal forums in 2024, trailing only stealer malware, according to Bitsight's 2025 State of the Underground report. The same report counted 384 unique malware varieties on the top forums that year, up from 349 in 2023. A good chunk of that growth is RATs, and a lot of that is thanks to the Malware-as-a-Service model, where operators sell subscriptions rather than one-off code. Customers get updates, support tickets, sometimes a tutorial. It resembles SaaS, except the S stands for something that steals your bank password rather than managing your calendar.

Here's the part that should keep RAT operators up at night: that subscription model creates paperwork. Customer lists, payment records, and support logs pile up. Every convenience they build for their buyers is a document trail for the FBI.

What investigators are actually looking for when they pursue RAT operators

Two kinds of evidence pile up around a RAT operation, and neither one is optional if you want to run a business.

The first is technical: malware samples, command-and-control servers, the infrastructure that actually runs the thing. The second is financial and commercial: forum posts, licensing records, payment trails, the stuff you'd expect from any online business, except this one traffics in stolen credentials instead of sneakers.

One of the FBI's go-to moves is refreshingly low-tech. Agents just buy the product. They pose as customers, purchase access to a live RAT, confirm it does what it claims (steals data, spies on webcams, whatever the sales pitch promises), and preserve the whole transaction as evidence. This is exactly what happened in the Warzone RAT case, and no exotic tradecraft was needed — just an agent with a credit card and a badge

Then there's infrastructure seizure, which tends to be the pivot point in these cases. Grab the domain, grab the server, and suddenly you're holding the customer database, the transaction logs, and often the operator's private messages. Forum posts don't help either, since ads for a RAT, offers of tech support, and tutorial threads walking buyers through setup all sit there indexed and searchable for years. Nothing on the internet forgets, and law enforcement has gotten very good at reading receipts.

Most of these cases also involve more than one country moving at the same time. That's standard now, because a RAT operator in one jurisdiction usually has customers, servers, and payment processors scattered across several others. Simultaneous action stops people from fleeing or deleting evidence before the knock on the door.

NanoCore and Orcus: how early cases established the developer-liability template

Taylor Huddleston built NanoCore RAT out of Hot Springs, Arkansas. He also built something called Net Seal, a licensing platform that helped distribute NanoCore and other malware to buyers. NanoCore itself was used to infect or attempt to infect more than 100,000 computers, and Net Seal helped one single customer reach around 3,000 people and infect roughly 16,000 machines.

Huddleston pleaded guilty and in February 2018 was sentenced to 33 months. The case turned on one admission: he knew people would use his software maliciously. Intent was the hinge the whole case swung on, and he sold it anyway.

A different defense came from John Revesz, who went by "Armada," with Orcus RAT in 2019. He marketed it as a legitimate Remote Administration Tool, the kind of thing IT departments use to manage employee laptops remotely. Fine premise, except the feature list gave him away. Orcus could disable a webcam's indicator light, so victims wouldn't know they were being watched, and it came bundled with DDoS-for-hire capabilities. Try explaining the legitimate business case for silently watching someone through their own camera without the light turning on. Investigators didn't buy it, and neither did the court.

When the RCMP searched Revesz's home, they found hard drives full of customer names, financial transactions, and operational records. The same commercial infrastructure that made his product easy to sell is what made him easy to convict.

Both cases set the template that's held ever since: if you sell a RAT knowing what buyers plan to do with it, or you provide support after the sale, you're on the hook. You don't need to personally run the attack. Selling the gun and cleaning it for the customer between uses counts.

NetWire and Warzone: how infrastructure seizure dismantles operations mid-flight

NetWire ran in plain daylight for over a decade. It sold openly on worldwiredlabs[.]com starting in 2012, priced between $80 and $140 depending on features, like a menu at a mid-range steakhouse. That kind of longevity and openness builds a customer base and a mountain of records.

In 2023, three countries moved at once. US authorities seized the domain, Swiss authorities seized the hosting server, and Croatian police arrested the man they say ran the site, for prosecution in Croatia. Three countries, three simultaneous actions, one dismantled operation.

Warzone RAT, also known as Ave Maria, ran the subscription model straight: $38 a month, or $196 if you paid for the year (a discount, because even malware vendors understand customer retention). That billing structure meant customer records existed somewhere, and investigators recovered them. The FBI also bought copies of Warzone directly, the same covert-purchase trick from the NanoCore playbook, which gave prosecutors a clean, independent demonstration of what the malware actually did.

Two men got arrested in 2024. Daniel Meli, in Malta, faces charges for selling and advertising an interception device, computer intrusion conspiracy, and causing unauthorized damage. Prince Odinakachi, in Nigeria, got charged for providing customer support to buyers, which tells you something important: tech support functions as co-conspiracy here, a criminal role in its own right. If you answer the phone when a hacker calls with a bug report, you're a defendant too.

The coordination on Warzone spanned more than ten countries plus Europol. Meli has since agreed to extradition to the United States. Look at NetWire and Warzone side by side and the pattern is obvious: the day a RAT goes commercial, its own operator starts building the case file against himself.

DanaBot: what a mature MaaS prosecution looks like at scale

If NanoCore and Orcus were proof of concept, DanaBot is the full-scale demonstration. The May 2025 indictment charged 16 defendants, making it the largest RAT-related prosecution on record and, so far, the most recent.

The numbers are big enough to make your head spin. More than 300,000 victim computers worldwide, at least $50 million in damages, and ransomware and fraud operations riding on the same infrastructure. This was a criminal business with a management structure.

The MaaS setup meant administrators leased out botnet access and support tools to affiliates, the way a franchise leases out a brand and a playbook. The FBI identified at least 40 paying affiliates using the platform. And here's the twist that reads like something out of a spy novel: a second, covert version of DanaBot targeted military, diplomatic, and government entities across North America and Europe. Some of these operators may have been running a criminal enterprise and something closer to intelligence work, at the same time, on the same code base.

One detail stands out. Kalinkin, one of two defendants still at large, reportedly works as an IT engineer at Gazprom. Criminal malware operations can sit two cubicles down from a day job at a state-connected energy company.

There's also the detail that should feel familiar by now: DanaBot's own infrastructure became part of the evidence trail investigators recovered. Sixteen defendants across a single indictment also marks a shift in scale, with prosecutors pursuing a wide net of participants rather than chasing individual coders.

The recurring self-exposure problem RAT operators cannot engineer away

Venn diagram: RAT Operations: Criminal Evidence vs. Business Infrastructure. Compares Criminal Evidence and Business Infrastructure; overlap: Self-Incriminating Overlap.

Every feature that makes a RAT sell, keylogging, credential theft, remote file access, always-on command-and-control communication, leaves behind logs, artifacts, and network signatures. The fingerprints are how the tool works.

Running it as a business only multiplies the problem. Domains, payment processors, support channels, licensing servers, each one is a lock waiting for law enforcement to pick, and each one is a potential seizure point.

The "it's just a legitimate remote admin tool" defense keeps failing for the same reason every time: the feature list gives it away. A webcam indicator bypass and silent keylogging with no audit trail are features built exclusively for covert surveillance, not the IT help desk. Orcus tried this defense and lost. DanaBot's developers didn't even need a courtroom to expose themselves; they infected their own machines and handed investigators a shortcut straight to their identities.

Even the ancillary products sell operators out. Tutorials, eBooks, how-to guides bundled alongside the RAT, like the ones tied to the Meli case, get read by prosecutors as evidence of intent, not merchandise alone. And geography is irrelevant, since defendants in this pattern have turned up in Malta, Nigeria, Russia, Croatia, Australia. Once US charges and extradition treaties are in motion, every hiding spot on the map is reachable.

Australia's Federal Police added a new wrinkle in April 2024: an undercover operation caught a developer early, filing twelve counts against him while the malware's damage was still limited. Sometimes the sting comes before the crime scales up.

What the enforcement pattern means for defenders tracking RAT activity

Read them as primary-source threat intelligence: confirmation of which RAT families were active, how big they got, and who was buying in.

The affiliate structure behind MaaS platforms means one piece of infrastructure can serve dozens of independent attackers at once, which cuts both ways. Take down the platform, and you stop all forty-plus of them simultaneously with a single takedown. That's a rare kind of efficiency in this line of work.

Infrastructure seizures also tend to produce indicator disclosures that defense teams can act on immediately. The Warzone and NetWire takedowns both generated usable indicators of compromise alongside the headlines.

Given that Bitsight's research shows MaaS growth carrying into 2025, this prosecution pipeline continues to accelerate. Anyone tracking indictments is watching a live threat signal. For security vendors and communicators, these cases hand you concrete material: named tools, verified victim counts, documented techniques. That's sturdier ground to build threat content on than another vendor's unnamed "sophisticated campaign," and primary-source grounding of this kind should anchor every piece a security company publishes.

The bigger takeaway for practitioners is simple. The same commercial and technical footprints that get RAT operators arrested (the C2 traffic, the licensing servers, the support logs, the self-inflicted malware infections) are exactly what detection engineering, threat hunting, and incident response teams should be building their playbooks around. The operators leave these footprints permanently, and that's good news for the people whose job is finding them.

Sources

  1. thehackernews.com
  2. fbi.gov
  3. thehackernews.com
  4. bitsight.com
  5. bitsight.com
  6. justice.gov
  7. intel471.com

More in malware operators and developers