Heisenberg RAT is the name used in a criminal-forum advertisement observed by KrakenLabs on July 15, 2026. The seller presents it as a modular Windows malware-as-a-service platform with remote control, hidden desktops, credential theft, loaders, and other components. Those capabilities are seller claims, not independently verified findings: no public sample, stable indicator set, delivery campaign, or confirmed victim activity was available in the checked source trail.[1]
If you saw the name in a security alert or report, preserve the exact filename, path, hash, detection text, download source, and time. The name alone does not prove that Heisenberg ran on the computer. If an unknown file did run, however, treat browser sessions, saved passwords, wallets, and other accounts as potentially exposed until the Windows system and the accounts are recovered separately.
What is verified about Heisenberg RAT?
KrakenLabs directly observed an advertisement from an actor using the HeisenbergSoft name on the Exploit underground forum. The advertisement offered a collection of components rather than one simple remote-access program. KrakenLabs reproduced the seller’s feature list and kept an important boundary in its report: the advertised capabilities had not been independently verified.
| Evidence level | What it supports |
|---|---|
| Observed | A HeisenbergSoft account advertised a modular Windows malware platform, named several components, and offered access for a monthly price. |
| Seller claimed | RAT and dual-HVNC access, browser and wallet theft, command execution, loaders, in-memory .HEIZ modules, multiple injection methods, anti-analysis features, and separate customer infrastructure. |
| Not established | That every feature works, that the service has customers, how it is delivered, which files or servers belong to it, how it persists, or whether a real victim campaign is active. |
This distinction matters during cleanup. A generic checklist should not invent Heisenberg-specific registry keys, services, scheduled tasks, domains, or filenames. None are public in the source used here. Investigate the artifacts on the affected computer instead of deleting broad Windows settings because they resemble a template from an unrelated malware family.
Heisenberg RAT is not the same as .heisenberg ransomware
The current Heisenberg RAT name comes from the 2026 platform advertisement. Older search results may use “Heisenberg” for ransomware-encrypted files or an extension ending in .heisenberg. The KrakenLabs source does not connect those ransomware references to HeisenbergSoft.
A file extension is not a malware identity. If documents were renamed or became unreadable, preserve copies and the ransom note and follow a ransomware response. If the concern is remote control, suspicious processes, unexpected sessions, or a file that ran, follow endpoint and account-compromise triage. For a broader explanation of the latter category, see our guide to RAT malware signs and removal.
Why hidden desktops and stolen browser sessions matter
HVNC usually describes a remote graphical session that operates away from the desktop the user can see. The seller claims two hidden-desktop components, but there is no public sample demonstrating how Heisenberg implements them. The practical risk is still understandable: remote-control malware can let an operator act with the permissions and signed-in sessions already present on a compromised computer. MITRE tracks adversarial use of remote-access tools as an interactive command-and-control technique.[2]
A hidden session may reduce obvious mouse movement or windows appearing on the visible desktop. If browser profiles are accessible, an operator may try to reuse authenticated sessions, view account data, or initiate transactions. Our MedusaHVNC browser-session analysis explains this risk with a sample-backed family; do not assume its artifacts also identify Heisenberg.
The advertised stealer and loader components raise two separate concerns if a future sample proves them:
- Information theft: passwords, cookies, autofill data, wallet extensions, documents, or tokens may leave the device.
- Follow-on payloads: a loader can introduce another malware family, so removing one visible executable may not end the incident.
These are risk categories, not proof that a particular computer is infected. A person who only read a report or saw the name online does not need malware removal. A person who opened an unknown installer but did not run it has a different exposure level from someone who executed it and then saw security alerts, disabled protections, new remote-access software, or unauthorized account activity.
What to do if you may have run a suspicious file
- Disconnect the suspected Windows computer from networks. Turn off Wi-Fi and unplug Ethernet. Do not sign in to email, banking, exchange, cloud, work, or wallet accounts from that device.
- Preserve useful evidence. Record the alert text, filename, full path, cryptographic hash when available, download URL, browser history, execution time, parent process, and any unexpected security exclusions, services, tasks, or remote-access programs. Photograph alerts before clearing them.
- Do not upload private files to random analysis sites. Business documents, wallet data, archives, and files containing customer information may expose more than the malware itself. Share samples only through an approved security or incident-response process.
- Run trusted security checks. Keep detections quarantined. Use the installed security product’s full or offline scan, then run a second trusted full-system scan. Do not restore a file merely because its name resembles a false positive.
- Review persistence and security changes. Check Startup apps, Task Scheduler, Windows services, installed applications, browser extensions, security exclusions, local administrator accounts, and legitimate remote-support tools you do not recognize. Remove only artifacts you can tie to the incident or that are clearly unauthorized.
- Reboot and scan again. A clean result after one scan is encouraging, but recurring alerts, recreated tasks, disabled security controls, or unexplained network connections mean the system is not yet trusted.
Clean the Windows system before restoring sessions
Deleting the original download is not sufficient after it ran. Another loader, startup entry, scheduled task, service, browser change, or bundled module may remain and restore access after reboot. Gridinsoft Anti-Malware can perform a full-system scan for malicious files and common persistence traces after the first containment checklist. It cannot determine whether every account was already used or reverse data theft.
If the process path is wrong, the name imitates a Windows component, or high CPU started after an unknown installer, scan for hidden miners, services, startup entries, and bundled components.
Scan the Windows systemFor a recent example of why a RAT cleanup must include the delivery path and account impact, see the TONResolver RAT recovery guide. The filenames and persistence from that case are not Heisenberg indicators; use it for response logic, not artifact matching.
Choose a clean reinstall from trusted installation media when administrative control may have been lost, security settings keep changing, detections return, unknown remote sessions occurred, or you cannot explain all persistence. Back up documents rather than executable files, scripts, installers, browser profiles, or unknown archives. Rebuild applications from original vendor sources.
Recover accounts and wallets from a clean device
Malware removal and account recovery are different jobs. Start recovery on a separate, known-clean phone or computer:
- Secure the primary email account and password manager first. Change unique passwords and revoke active sessions.
- Reset Microsoft, work, cloud, repository, social, and messaging accounts that were used on the suspected host. Review sign-in history, app passwords, recovery methods, OAuth grants, API tokens, and forwarding rules.
- Contact banks or card issuers about unauthorized activity. Review exchange accounts, withdrawal addresses, API keys, and trusted devices.
- If a wallet seed phrase or private key was present on the device, create a new wallet on a clean system or hardware wallet and move assets. A password change cannot invalidate an exposed seed phrase.
- Replace MFA recovery codes or authentication seeds if they may have been accessible. Do not approve unexpected prompts while recovery is underway.
Prioritize accounts by consequence, not convenience. Our overview of current infostealer risks includes a wider clean-device recovery sequence for browser data and stealer logs.
How to verify cleanup
Because no stable Heisenberg IOC set is public, cleanup cannot depend on searching for one magic filename. Build confidence from several independent checks:
- full and post-reboot scans are clean;
- security protection, firewall, and update settings stay enabled;
- Startup items, tasks, services, local admins, extensions, and remote tools are all explained;
- network activity no longer includes unexplained long-lived connections;
- browser profiles are rebuilt or restored only after the system is trusted;
- important sessions, tokens, passwords, and wallet secrets have been revoked or replaced from a clean device;
- account monitoring shows no new unauthorized sign-ins or transactions.
If one of those conditions cannot be met, keep the device isolated and involve an incident responder. For a business endpoint, preserve logs and coordinate with the organization before wiping the system; rebuilding too early can erase evidence needed to scope other affected accounts or computers.
FAQ
Is Heisenberg RAT confirmed malware?
KrakenLabs confirmed that HeisenbergSoft advertised a Windows malware platform. The advertised feature set is not independently verified, and no public sample, IOC set, delivery campaign, or victim activity was available in the checked sources.
Does a .HEIZ file prove Heisenberg infection?
No. .HEIZ is a module format claimed in the seller’s advertisement, not a published detection rule. Preserve the file and its context, but do not identify an incident from an extension alone.
Can antivirus scanning recover stolen passwords or wallet funds?
No. Scanning can find malicious files and persistence, but it cannot revoke stolen sessions, restore transferred funds, or make an exposed seed phrase secret again. Recover accounts and wallets separately from a clean device.
Should I reinstall Windows after a suspected RAT?
Reinstall when the file ran with elevated rights, security controls were changed, alerts or persistence return, remote access is suspected, or you cannot explain the system state. A controlled rebuild is safer than assuming one deleted executable was the whole incident.
References
- KrakenLabs. “New malware-as-a-service offering: Heisenberg RAT.” X, July 15, 2026. Accessed August 4, 2026. https://x.com/KrakenLabs_Team/status/2077397175860879476
- MITRE ATT&CK. “Remote Access Tools (T1219).” MITRE, last modified May 12, 2026. Accessed August 4, 2026. https://attack.mitre.org/techniques/T1219/

