216.73.216.6

Tracking an evolving Discord-based RAT family

· Published 31/10/2025 09:32 · Modified 31/10/2025 11:30

Export JSON

Essential information

Published
31/10/2025 09:32
Modified
31/10/2025 11:30
Tags
2025-10-31 discord minecraft rat propionanilide propionanilide rat std rat uwudisrat
Related entities
1 intrusion sets (apt), 3 techniques (mitre), 4 malware

Description

ReversingLabs has identified four new remote access trojans (RATs) utilizing for command and control. These RATs, operated by the STD Group, include , , , and . The malware, written in C++, uses a ROT23 cipher to encode bot tokens for C2 communication. The analysis reveals the evolution from single payloads to experimentation with packers, particularly in the case of . The report provides detailed insights into each RAT variant, including file indicators and YARA rules for detection.

External references