216.73.216.6

The RAT race: What happens when RATs go undetected

· Published 30/11/2024 06:27 · Modified 02/12/2024 12:48

Export JSON

Essential information

Published
30/11/2024 06:27
Modified
02/12/2024 12:48
Tags
2024-11-30 CVE-2024-38213 dcrat purelog stealer rat xworm
Related entities
16 techniques (mitre), 4 malware

Description

This analysis explores a sophisticated cyberattack attempt involving multiple Remote Access Tools (RATs) and a stealer. The attack chain begins with an email containing an exploit for , bypassing Windows' Mark of the Web security feature. The malware uses WebDav directories and Cloudflare's free tunnel service to host and execute various RATs, including , AsyncRAT, and , as well as the . The payloads are delivered through obfuscated batch files and compiled Python scripts, using memory-only execution techniques to evade detection. The attackers employ multiple C2 domains using the DuckDNS service, pointing to IP addresses in the U.S. The analysis highlights the importance of early threat detection in preventing potential ransomware deployment or data exfiltration.

External references