Report: Newly Discovered GlassRAT Lurked For Years, Undetected
ID: 027267ee-3e99-51d5-9e7d-66d827f001da
STIX ID: report--027267ee-3e99-51d5-9e7d-66d827f001da
Feed Name: Security Ledger
Threat Score
RSA Security discovered GlassRAT, a remote-access trojan reportedly active since 2012 and operating stealthily for nearly three years, which targets Chinese nationals at large multinational corporations; the threat uses a dropper masquerading as Adobe Flash (Flash.exe) and a malicious DLL signed with a legitimate/compromised certificate to evade detection, and RSA links it to prior families (Mirage, Magicfire, PlugX), suggesting a sophisticated, persistent espionage campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
