Malware Spotlight: A Deep-Dive Analysis of WezRat
ID: 5a8fc1c2-3398-5a88-9da2-3b3567d9b28a
STIX ID: report--5a8fc1c2-3398-5a88-9da2-3b3567d9b28a
Feed Name: Check Point Research
This Check Point Research report analyzes WezRat, a modular infostealer/backdoor used by the Iranian-linked group Emennet Pasargad, describing a phishing campaign that distributed a malicious MSI disguised as a Chrome update to Israeli organizations. The analysis covers the backdoor's C++ implementation, DLL-based modular features (screenshots, keylogger, clipboard and cookie theft, file upload), C2 protocol and endpoints, evolution of samples and backend code, and provides IOCs (SHA256 hashes and server domains) and mitigation notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
