216.73.216.36

MostereRAT Deployed AnyDesk/TightVNC for Covert Full Access

· Published 09/09/2025 04:48 · Modified 09/09/2025 12:08

Export JSON

Essential information

Published
09/09/2025 04:48
Modified
09/09/2025 12:08
Tags
2025-09-09 anydesk epl evasion techniques mostererat mtls phishing remote access tightvnc
Related entities
12 observables, 14 techniques (mitre), 1 malware, 1 others

Description

A sophisticated campaign targeting Japanese users employs , a Trojan that utilizes advanced . The attack chain involves multiple stages, including an Easy Programming Language () payload, security tool disabling, and -secured C2 communications. The malware can deploy popular tools like and , granting attackers full system control. It employs techniques such as running as TrustedInstaller, blocking AV traffic, and creating hidden administrator accounts. The campaign's complexity and use of legitimate tools make detection and prevention challenging, highlighting the importance of user education and up-to-date security solutions.

External references