s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.power_rat

📛 Threat Title

Malware family: PowerRAT

Category: PowerRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.power_rat`. Printable name: PowerRAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cybercory.com

    Establish Incident Response Protocols: Develop and test incident response protocols to quickly respond to and mitigate the impact of malware infections. Conclusion: The abuse of open-source tools like Gophish, combined with the delivery of powerful malware such as PowerRAT and DCRAT, highlights the evolving complexity of cyber threats.

  • web:hivepro.com

    Once the victim enables macros, the embedded document decrypts its content, deploying a PowerShell-based reverse shell known as PowerRAT . This tool facilitates remote control over the compromised system and employs various techniques to evade detection, such as hiding malicious files using environment variables and encrypting payloads.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the PowerRAT malware family including references, samples and yara signatures.

  • web:securitricks.com

    Description A new phishing campaign targeting Russian-speaking users employs the open-source Gophish framework to deliver DarkCrystal RAT and a novel remote access trojan called PowerRAT . The attack utilizes modular infection chains, either through malicious Microsoft Word documents or HTML files with embedded JavaScript. The campaign exploits Gophish to send phishing emails and deploy the ...

  • web:www.broadcom.com

    A recent report by (CTA) member Cisco Talos has recently disclosed a new phishing campaign abusing the open-source phishing readiness assessment framework named 'Gophish' to deploy one of two attack chains. The first uses Pidief infected Office docs to deploy a newly discovered PowerShell RAT dubbed 'PowerRAT' while the second employs malicious HTML files and GOLoader to deploy DCRAT. Symantec ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.itfunk.org

    The Concrete Threat: PowerRat One notable example of Trojan malware is PowerRat , a sophisticated and persistent threat known for its stealthy operations. PowerRat is primarily designed to steal sensitive information, including login credentials, banking details, and other personal data.

  • web:www.researchgate.net

    Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...

  • web:www.scworld.com

    Malicious emails with phishing links have been leveraged to launch either remote access trojan but while DCRat has been deployed through a remote HTML file, PowerRAT has been spread through a malicious Microsoft Word file that executes a rogue Visual Basic macro.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.