Python-Based PyRAT Emerges as Cross-Platform Threat With Advanced Remote Access Capabilities
ID: 49860571-adaa-5c75-9e3b-87f5cd62bcde
STIX ID: report--49860571-adaa-5c75-9e3b-87f5cd62bcde
Feed Name: GBHackers
This analysis describes a cross-platform Python-derived Remote Access Trojan (PyRAT) compiled for Windows and Linux that performs system fingerprinting, generates semi-persistent victim IDs, communicates with C2 via plaintext HTTP POST to /api/{uid}/hello, implements user-level persistence (Linux XDG Autostart and Windows HKCU Run), supports remote command execution, file transfer and ZIP-based exfiltration, and includes uninstall/cleanup routines; the report notes active antivirus detections and in-the-wild deployment by organized cybercriminals, posing a significant risk to affected endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
