logo

Python-based PyRAT with Cross-Platform Capabilities and Extensive Remote Access Features

ID: 0415e47d-99f7-517a-8953-35d22a507db2

STIX ID: report--0415e47d-99f7-517a-8953-35d22a507db2

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-29

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A newly identified Python-based remote access trojan (RAT) discovered by K7 Security Labs targets Windows and Linux systems, establishing unencrypted HTTP command-and-control using JSON and a semi-persistent identifier combining username and MAC address. The malware fingerprints victims, achieves user-level persistence (a deceptive ~/.config/autostart/.desktop on Linux and a Run-key registry entry named "lee" on Windows), and supports file enumeration, upload/download, ZIP exfiltration, and screenshot capture; it was packaged with PyInstaller for Python 2.7 and was found during VirusTotal investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.