← Back to feed
Threat Actors & CampaignsEmerging1 sourceJun 25, 2026 · 09:30via Group-IB

Millenium: A RAT Rewritten, A Threat Multiplied

Brief

Group-IB analyzes Millenium RAT version 4. *, a remote access trojan that has undergone an architectural shift from . NET to native C++, while continuing to leverage the Telegram Bot API for command and control, requiring no dedicated server infrastructure. This blog also profiles the developer “ShinyEnigma”, and threat actor cluster “Y2K Operators” responsible for active Millenium RAT exploitation campaigns.

Over 62,000 compromised endpoints across more than 160 countries have been identified, with infections accele

Read more on Group-IB