s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.poet_rat

📛 Threat Title

Malware family: Poet RAT

Category: Poet RAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.poet_rat`. Printable name: Poet RAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    PoetRAT is a remote access trojan ( RAT ) that was first identified in April 2020. PoetRAT has been used in multiple campaigns against the private and public sectors in Azerbaijan, including ICS and SCADA systems in the energy sector. The STIBNITE activity group has been observed using the malware . PoetRAT derived its name from references in the code to poet William Shakespeare. [1] [2] [3]

  • web:blog.sucuri.net

    Learn what a Remote Access Trojan is, how RATs work, the risks they pose, and how to protect against infections. We cover the basics, examine real incidents where websites spread RAT infections, and provide practical advice for securing your devices against a RAT .

  • web:blog.talosintelligence.com

    The PoetRAT malware was used against this country a few months ago and new campaigns from this threat actor appeared after the armed conflict. The malware slightly evolved since our previous publication. The developer implemented a new exfiltration protocol to hide its activities.

  • web:infosecwriteups.com

    Hello Hackers Yuvaraj here, Today we are going to analyze the Poetrat malware . Poetrat is a Remote Access Trojan(RAT) which means an attacker can able to control and monitor the victim's machine. This malware targets Azerbaijan public sector and other important organizations. The malware is a word document. When opening the document it will execute a malicious VBA script which will drop the ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Cisco Talos has discovered a Python-based RAT they call Poet RAT . It is dropped from a Word document and delivered including a Python interpreter and required libraries. The name originates from references to Shakespeare. Exfiltration happens through FTP.

  • web:sslinsights.com

    Learn about Remote Access Trojan types, security measures to prevent RAT attacks, and effective removal steps to protect your devices.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.malwarebytes.com

    Get everything you need to know about Remote Access Trojans ( RAT ) from what are they, the history of RAT , common infection methods, how to remove them & much more.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.pcrisk.com

    What is PoetRAT ? PoetRAT is the name of a Remote Access Trojan ( RAT ). This type of malware allows cyber criminals to monitor and control the victim's computer. In most cases, RATs such as PoetRAT are distributed to infect computers with other malware and/or steal sensitive information. This particular malware can be used to log keystrokes, steal passwords, access victims' webcams, manage files ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.