logo

ElizaRAT Exploits Google, Telegram, & Slack Services For C2 Communications

ID: 4411a211-99ba-5d61-90dd-05553c260814

STIX ID: report--4411a211-99ba-5d61-90dd-05553c260814

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2024-12-03

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

APT36 has updated its toolkit with ElizaRAT and related payloads that use Slack API-based and Google Cloud C2 channels, dropper components, and persistence via rundll32 and scheduled tasks to target Indian government, diplomatic, and military systems. The report includes indicators (e.g., SlackAPI.dll MD5 2b1101f9078646482eb1ae497d44104), filenames (%appdata%\CircleCpl, SlackFiles.dll, circulatedrop.dll), Slack channel IDs, and mentions VPS/IP infrastructure tied to active campaigns and payload distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.