216.73.217.22

The Abuse of ITarian RMM by Dolphin Loader

· Published 19/08/2024 13:24 · Modified 19/08/2024 13:55

Export JSON

Essential information

Published
19/08/2024 13:24
Modified
19/08/2024 13:55
Tags
2024-08-19 autoit darkgate dolphin loader evade itarian lummac2 malware-as-a-service python redline rhadamanthys rmm sectoprat stealthy
Related entities
24 observables, 1 intrusion sets (apt), 11 techniques (mitre), 6 malware

Description

This report explores how the , a loader, abuses the legitimate Remote Monitoring and Management () software to distribute various malware payloads. The loader leverages the built-in functionality of tools, such as remote command execution and system monitoring, to operate stealthily and detection. The report provides an in-depth analysis of the 's techniques, including the use of scripts for payload execution and the abuse of the software's 'Procedures' feature to run malicious scripts on registered devices.

External references