ElizaRAT Exploits Google, Telegram, & Slack Services For C2 Communications
ID: 4411a211-99ba-5d61-90dd-05553c260814
STIX ID: report--4411a211-99ba-5d61-90dd-05553c260814
Feed Name: GBHackers
APT36 has updated its toolkit with ElizaRAT and related payloads that use Slack API-based and Google Cloud C2 channels, dropper components, and persistence via rundll32 and scheduled tasks to target Indian government, diplomatic, and military systems. The report includes indicators (e.g., SlackAPI.dll MD5 2b1101f9078646482eb1ae497d44104), filenames (%appdata%\CircleCpl, SlackFiles.dll, circulatedrop.dll), Slack channel IDs, and mentions VPS/IP infrastructure tied to active campaigns and payload distribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
