Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Malware
/
MarkiRAT
Malware
MarkiRAT
Indicators of Compromise
5
Domain
attacker-controlled domain
Filename
ClaudeDesktop.exe
IP
hardcoded IP
Package
@apexfdn/apex
Package
@copilot-mcp/apex
MITRE ATT&CK TTPs
5
T1001.003
Protocol or Service Impersonation
Command And Control
T1027
Obfuscated Files or Information
Defense Evasion
T1053.005
Scheduled Task
Execution
T1059.001
PowerShell
Execution
T1071.004
DNS
Command And Control
Source Articles
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Recent cyber threats include malicious npm and PyPI packages delivering infostealers, counterfeit VS Code extensions exfiltrating machine data, and Android spyware disguised as legitimate safety apps. Iranian-affiliated actors are targeting PLC systems in critical infrastructure, while attackers leverage AI models for prompt injection and malware development. Campaigns also involve malvertising distributing SectopRAT and MarkiRAT, DNS tunneling by TrickBot for C2 communication, and exploitation of trust in legitimate platforms to deliver malware.
hacker-news
·
5d ago