The US government says it has seized and taken down the dangerous Warzone RAT malware

Malware
(Image credit: Pixabay)

Two hackers selling the Warzone RAT malware-as-a-service (MaaS) and offering customer support for their clients have been arrested, the US Department of Justice (DoJ) has announced. 

In a press release published on the DoJ website, it was said that two individuals, Daniel Meli (27) and Prince Onyeoziri Odinakachi (31), were charged with unauthorized damage to protected computers, with Meli also being charged of “illegally selling and advertising an electronic interception device and participating in a conspiracy to commit several computer intrusion offenses."

Their infrastructure was also seized and subsequently dismantled.

"Ancient" malware

The malware they sold is called Warzone Remote Access Trojan (RAT), and it was capable of stealing sensitive data and controlling compromised endpoints remotely. The attackers could use Warzone to browse victim file systems, grab screenshots, log keystrokes, steal login credentials, and even access people’s webcams. They sold it for $38 a month, or $196 a year. 

Multiple state and international law enforcement agencies participated in the operation, the DoJ confirmed, including the FBI, Europol, and national law enforcement in Australia, Canada, Croatia, Finland, Germany, Japan, Malta, the Netherlands, Nigeria, Romania, and Europol. The two hackers were arrested in Mali and Nigeria, allegedly. 

During the operation, the police also seized the domains (warzone[.]ws, among others), that were used to sell the malware, the DoJ confirmed. 

Warzone RAT has been around for years, with news reports dating back years. The Hacker News claims Warzone RAT was first observed in January 2019, when a threat actor used it to target an Italian organization in the oil and gas sector. The DoJ argues that Meli offered MaaS services since at least 2012, via hacking forums, through e-books, and other methods. Discord was also mentioned as a way of communicating with the sellers.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Ransomware
8base ransomware site taken down in global police operation
Cyber crime concept with man in handcuffs
Global police operation takes down major cybercrime and hacking forums
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
Representational image of a cybercriminal
US, UK crack down on Russian bulletproof hosting service ZServers for LockBit partnership
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
A major FBI operation has deleted Chinese malware from thousands of US computers
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring