Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Malware
/
ReverseRAT
Malware
ReverseRAT
Indicators of Compromise
8
Domain
dns[.]educationportals[.]biz
Domain
docsportal[.]in
Filename
appT.bat
Filename
commskl.docx
Filename
commskll.docx.lnk
Filename
ioluegnt.dll
Filename
startT.hta
IP
45[.]61[.]157[.]22
MITRE ATT&CK TTPs
6
T1027
Obfuscated Files or Information
Defense Evasion
T1055.001
Dynamic-link Library Injection
Defense Evasion
T1059.001
PowerShell
Execution
T1071.001
Web Protocols
Command And Control
T1547.001
Registry Run Keys / Startup Folder
Persistence
T1566
Phishing
Initial Access
Source Articles
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
The Pakistan-based threat actor SideCopy has expanded its targeting to include academic institutions in India, using spear-phishing campaigns to deliver a remote access trojan called ReverseRAT. The attack chain begins with a malicious LNK file disguised as a PDF document, which executes an obfuscated HTA file via mshta.exe to load a reflective DLL payload. The malware establishes persistence through Windows Registry Run Keys, performs multi-stage in-memory deobfuscation, and exfiltrates data to a C2 server using encrypted traffic over port 5863.
hacker-news
·
4h ago