216.73.216.6

RunningRAT’s Next Move: From Remote Access to Crypto Mining for Profit

· Published 06/11/2024 16:21 · Modified 06/11/2024 17:34

Export JSON

Essential information

Published
06/11/2024 16:21
Modified
06/11/2024 17:34
Tags
2024-11-06 cryptocurrency mining remote access trojan runningrat xmrig
Related entities
11 observables, 19 techniques (mitre), 2 malware, 2 others

Description

, a initially observed in 2018 targeting the Pyeongchang Winter Olympics, has evolved its capabilities to include . This shift indicates an expansion of the malware's operational focus. The analysis reveals the discovery of samples in open directories, detailing its execution process, network communications, and connection to tools. The malware's infrastructure includes command and control servers hosting mining software, suggesting a new direction towards financial gain through compromised systems. The findings highlight the adaptability of established malware and the importance of continued monitoring for emerging threats.

External references