WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 FBI FLASH – Identification and Disruption of the Warzone Remote Access Trojan (RAT)
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

FBI FLASH – Identification and Disruption of the Warzone Remote Access Trojan (RAT)

Author: Chase Snow

Created: Thursday, February 15, 2024 - 19:16

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

The FBI has published a TLP:CLEAR FLASH to disseminate indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with the Warzone Remote Access Trojan (RAT), also identified as “Ave Maria” through open-source reporting and FBI investigation.

On 7 February 2024, the FBI and international partners executed a coordinated operation to disrupt Warzone RAT infrastructure worldwide. The FBI is releasing this product to maximize awareness on the service and to seek additional reporting from victims.

Beginning in October 2018, the Warzone service offered a malware-as-a-service (MaaS) remote access trojan, along with other malware products and attracted a customer database of over 7,000 users. The products were used by cyber criminals and nation state actors to engage in remote control, keylogging, data theft, or other methods of discovering and collecting victim system information. Warzone has been adept at exploiting old vulnerabilities from 2017 and 2018 on Microsoft components/devices left unpatched.

The FBI includes technical details in the FLASH report and has also established a dedicated page for organizations or victims of the Warzone RAT to report key findings using their Warzone RAT Victim Reporting Form. See the attached FLASH report below.

Attached Files:

Identification_and_Disruption_of_the_Warzone_Remote_Access_Trojan_RAT

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar