s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.electro_rat

📛 Threat Title

Malware family: ElectroRAT

Category: ElectroRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.electro_rat`. Printable name: ElectroRAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:any.run

    Online sandbox report for All. ElectroRAT .zip, verdict: Malicious activity

  • web:e.cyberint.com

    INTRODUCTION Identified as targeting cryptocurrency users through nefarious cross-platform applications, a remote access trojan (RAT) dubbed 'ElectroRAT' has recently been in the headlines following an investigation into the threat by researchers at Intezer.

  • web:fintechs.fi

    Called " ElectroRAT ," as it infects Electron applications, the virus is a remote access trojan (RAT) that was discovered in December 2020 and targets Windows, Linux, and macOS users.

  • web:github.com

    Revamp of malware folder + new samples b013182 · 5 years ago History dda14413450a11f336a8305cf274943d614905c3429d4f0efeffe6bf4b8b7bdc All. ElectroRAT .zip

  • web:intezer.com

    These malware are stealers mainly purchased on the Dark Web as off-the-shelf malware . ElectroRAT shares similar functionalities to these well-known trojans, however, it's written from scratch in Golang. We assume a reason for this is to target multiple operating systems, since Golang is incredibly efficient for multi-platform use.

  • web:malpedia.caad.fkie.fraunhofer.de

    ElectroRAT Propose Change According to PCrisk, ElectroRAT is a Remote Access Trojan (RAT) written in the Go programming language and designed to target Windows, MacOS, and Linux users. Cyber criminals behind ElectroRAT target mainly cryptocurrency users. This RAT is distributed via the trojanized Jamm, eTrader, and DaoPoker applications.

  • web:www.bitdefender.com

    According to the advisory (FLASH-20260219-001), cybercriminals are increasingly deploying sophisticated malware — particularly variants of the Ploutus family — to force Automated Teller Machines (ATMs) to dispense cash without any legitimate transaction or bank authorization.

  • web:www.bleepingcomputer.com

    Named ElectroRAT after being discovered in December, the cross-platform RAT malware is written in Golang and it was used as part of a campaign that has been targeting cryptocurrency users since ...

  • web:www.broadcom.com

    In this attack, ElectroRAT was distributed through trojanized applications that are related to cryptocurrency activities such as trading and gambling. ElectroRAT is capable of keylogging, downloading and uploading files, and executing commands on the compromised machine.

  • web:www.pcrisk.com

    ElectroRAT has capabilities such as uploading files from disk, downloading files and executing commands on the victim's computer, keylogging (keystroke logging) and taking screenshots. Malware with keylogging features allows cyber criminals to record keyboard input, which is employed to steal personal information that victims enter.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.