TF-MAL-py.poet_rat
📛 Threat Title
Malware family: Poet RAT
Description
ThreatFox malware family `py.poet_rat`. Printable name: Poet RAT.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
PoetRAT is a remote access trojan ( RAT ) that was first identified in April 2020. PoetRAT has been used in multiple campaigns against the private and public sectors in Azerbaijan, including ICS and SCADA systems in the energy sector. The STIBNITE activity group has been observed using the malware . PoetRAT derived its name from references in the code to poet William Shakespeare. [1] [2] [3]
-
web:blog.sucuri.net
Learn what a Remote Access Trojan is, how RATs work, the risks they pose, and how to protect against infections. We cover the basics, examine real incidents where websites spread RAT infections, and provide practical advice for securing your devices against a RAT .
-
web:blog.talosintelligence.com
The PoetRAT malware was used against this country a few months ago and new campaigns from this threat actor appeared after the armed conflict. The malware slightly evolved since our previous publication. The developer implemented a new exfiltration protocol to hide its activities.
-
web:infosecwriteups.com
Hello Hackers Yuvaraj here, Today we are going to analyze the Poetrat malware . Poetrat is a Remote Access Trojan(RAT) which means an attacker can able to control and monitor the victim's machine. This malware targets Azerbaijan public sector and other important organizations. The malware is a word document. When opening the document it will execute a malicious VBA script which will drop the ...
-
web:malpedia.caad.fkie.fraunhofer.de
Cisco Talos has discovered a Python-based RAT they call Poet RAT . It is dropped from a Word document and delivered including a Python interpreter and required libraries. The name originates from references to Shakespeare. Exfiltration happens through FTP.
-
web:sslinsights.com
Learn about Remote Access Trojan types, security measures to prevent RAT attacks, and effective removal steps to protect your devices.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.malwarebytes.com
Get everything you need to know about Remote Access Trojans ( RAT ) from what are they, the history of RAT , common infection methods, how to remove them & much more.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.pcrisk.com
What is PoetRAT ? PoetRAT is the name of a Remote Access Trojan ( RAT ). This type of malware allows cyber criminals to monitor and control the victim's computer. In most cases, RATs such as PoetRAT are distributed to infect computers with other malware and/or steal sensitive information. This particular malware can be used to log keystrokes, steal passwords, access victims' webcams, manage files ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.