Python-based PyRAT with Cross-Platform Capabilities and Extensive Remote Access Features
ID: 0415e47d-99f7-517a-8953-35d22a507db2
STIX ID: report--0415e47d-99f7-517a-8953-35d22a507db2
Feed Name: cybersecurityNews.com
A newly identified Python-based remote access trojan (RAT) discovered by K7 Security Labs targets Windows and Linux systems, establishing unencrypted HTTP command-and-control using JSON and a semi-persistent identifier combining username and MAC address. The malware fingerprints victims, achieves user-level persistence (a deceptive ~/.config/autostart/.desktop on Linux and a Run-key registry entry named "lee" on Windows), and supports file enumeration, upload/download, ZIP exfiltration, and screenshot capture; it was packaged with PyInstaller for Python 2.7 and was found during VirusTotal investigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
