A new and particularly dangerous threat is at the center of the international cybersecurity community. The Millennium RAT, an advanced Access Trojan , is spreading rapidly worldwide, having already infected more than 62,000 devices in over 160 countries. Researchers' data shows that its activity is not only not decreasing, but is accelerating, with more than 39,000 new infections recorded in the first quarter of 2026 alone.

Experts warn that this is one of the most organized malware distribution operations in recent years, as it combines low acquisition costs, sophisticated obfuscation techniques, and aggressive social engineering methods.
From a simple RAT to a sophisticated cyber threat
The Millennium RAT was first detected in late 2023 by cybersecurity firm CYFIRMA, when analysts recorded version 2.4 of the software.
In less than three years, however, the malware has evolved significantly. Today's version 4 is essentially a completely redesigned spying platform, designed exclusively for Windows.
See also: ATM Jackpotting gang members convicted of Ploutus malware attacks
According to ’s research Group-IB, the campaign is being carried out by a group known as Y2K Operators, while the main creator of the malware uses the alias “shinyenigma.” Most worryingly, the Millennium RAT is being advertised publicly on underground forums and software development platforms, allowing any cybercriminal to gain access to the tool.
Malware-as-a-Service for just a few dollars
The spread of the Millennium RAT is largely due to the business model followed by its creators.
The malware is available as a Malware-as-a-Service (MaaS)subscription service. Interested parties can get it for just $50 for the first month of use, renew their subscription for $10, or even purchase permanent access for $90.
The low cost results in a constantly expanding number of its users, as even people without special technical knowledge can acquire a powerful cyberattack tool.

The move to C++ makes it harder to detect
One of the most important technical changes in the new version is the complete rewriting of the code from .NET to native C++.
This change makes the malware lighter, faster, and most importantly, harder to detect than many protection solutions, as it no longer requires the presence of the .NET Framework on the victim's computer.
At the same time, its creators use advanced encryption techniques, Base64 encoding, and custom XOR algorithms to constantly change the file's digital fingerprint, bypassing detection based on known signatures.
Telegram becomes a control tool
Another feature that makes Millennium RAT stand out is the way it communicates with its administrators. Instead of using dedicated command-and-control servers, the malware leverages the Telegram Bot API to send and receive commands.
See also: VS Code Tasks: Stolen npm and Go packages download Python infostealer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In this way, malicious traffic looks like normal online communication, making it significantly more difficult for security systems to distinguish the difference between legitimate and malicious activity.
What can Millennium RAT do?
The capabilities of this trojan are particularly extensive. Once installed on a computer, it can steal saved passwords and cookies from popular browsers, record every keystroke the user types via a keylogger, take screenshots, activate the camera and microphone, gain access to chats and data from apps like Telegram and Discord, and even encrypt files, paving the way for future ransomware attacks.
At the same time, it permanently installs itself on the system by copying itself to the %APPDATA% and creating auto-start entries in the Windows registry, so that it is activated every time the computer is started.
Social engineering remains the most powerful weapon
Unlike other sophisticated threats, the Millennium RAT does not rely on unknown vulnerabilities or zero-day attacks.
Its creators mainly exploit human carelessness. The malware is distributed disguised as software cracks, hacking tools, credit card generators, cryptocurrency applications, or gaming utilities.

In several cases, fake PDFs or file shortcuts have even been detected that silently execute PowerShell commands in the background, installing malware while the user believes they opened a simple document.
Even more worrying is the practice of modifying known remote access tools. Operators are secretly embedding the Millennium RAT into legitimate applications and redistributing them online, turning even would-be cybercriminals into… victims of their own tools.
See also: STOCKSTAY: Turla's new backdoor against Ukraine
How can users be protected?
Experts emphasize that protection against the Millennium RAT starts with basic cybersecurity practices. Avoiding downloading software from untrusted sources, account -administrator for daily tasks, regularly installing security updates , and enabling multi-factor authentication (MFA) can significantly reduce the risk.
The rapid spread of the Millennium RAT confirms that cybercrime is evolving at a pace reminiscent of legitimate technology businesses. The availability of malware as a subscription service, continuous upgrades, and the exploitation of popular platforms like Telegram show that cybercriminals are now investing in professional development methods, making user awareness and vigilance more important than ever.
