Pulsar RAT Attacking Windows Systems via Per-user Run Registry Key and Exfiltrates Sensitive Details
ID: 6b8d5db4-1c2c-5735-92aa-513663e768e1
STIX ID: report--6b8d5db4-1c2c-5735-92aa-513663e768e1
Feed Name: cybersecurityNews.com
Pulsar RAT is a Windows-focused remote access trojan that deploys an obfuscated batch and PowerShell-based multi-stage loader, performs in-memory Donut shellcode injection into legitimate processes (e.g., explorer.exe), and establishes persistence via per-user Run registry keys and scheduled tasks. The malware implements extensive anti-analysis controls, steals credentials, wallets, and tokens, and exfiltrates collected data over Discord and Telegram channels; observed command-and-control infrastructure includes 185.132.53.17:7800.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
