Hackers Attacking IT & OSINT Professionals with New PyStoreRAT to Gain Remote Access
ID: 002eae8a-f06f-555f-83c2-ef160814fab4
STIX ID: report--002eae8a-f06f-555f-83c2-ef160814fab4
Feed Name: cybersecurityNews.com
Threat Score
A sophisticated supply-chain campaign is reactivating dormant GitHub accounts to publish AI-generated projects that later receive malicious maintenance commits installing a backdoor called PyStoreRAT; the loader profiles victims, deploys payloads including the Rhadamanthys stealer, spreads via removable drives, adapts execution to avoid AVs, and uses resilient rotating C2 nodes — targeting IT administrators and OSINT professionals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
