Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Jan 10, 2023 | Updated Aug 18, 2025

Trojan:Win64/NjRat.NEBG!MTB

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Trojan:Win64/NjRat.NEBG!MTB is an advanced 64-bit variant of the NjRAT remote access trojan, which is a threat that was first reported in 2012, with operators tied to cyber activities within the Middle East. This trojan was conceived for stealth and persistence. It is only one of the hundreds of NjRAT family variants, most of which use the .NET framework for its speed and cross-platform capabilities, requiring only the presence of the Microsoft .NET runtime library to run. NjRAT has a designation of "commodity RAT" because the source code has leaked to the public domain, allowing threat actors to adjust and customize it for their specific campaigns.  

Delivery mechanisms of this trojan include phishing campaigns, drive-by download, USB auto-run exploits, and  through steganography like hiding payloads in an image's bitmap resources. Core functionalities include substantial remote control capabilities, credential harvesting, keylogging, webcam activation, cryptocurrency theft (a common use case), and secondary payloads with ransomware or coin miners. The "!MTB" designation refers to behavioral detection where, unlike a traditional signature match, one can identify the trojan by unknown changes to the registry or suspicious network activities. 

  • Disconnect from networks/internet. 
  • Check scheduled tasks (schtasks /query) and remove malicious entries 
  • End task all instances of svchos.exe in Task Manager and use File Explorer to delete it from Windows. Boot to Safe Mode as needed and perform that action. 
  • Restore the Windows Hosts file (C:\Windows\System32\drivers\etc\hosts) from backups 
  • Reset all passwords stored in browsers or cached applications. 

Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. 

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help. 

Follow us