216.73.216.6

New I2PRAT communicates via anonymous peer-to-peer network

· Published 16/12/2024 10:31 · Modified 16/12/2024 12:33

Export JSON

Essential information

Published
16/12/2024 10:31
Modified
16/12/2024 12:33
Tags
2024-12-16 i2p i2prat phishing privateloader uac bypass
Related entities
12 techniques (mitre), 2 malware

Description

A novel malware strain, , has been discovered utilizing the network for command and control communication. The infection begins with a email leading to a fake CAPTCHA page, which tricks users into executing a malicious PowerShell script. The malware employs , Microsoft Defender evasion techniques, and WFP filters to render the victim's machine vulnerable. The RAT's modular structure includes various plugins for different functionalities, such as downloading files, enabling RDP, managing user accounts, and creating scheduled tasks. The malware has been active since at least March 2024 and may be distributed through .

External references