Distribution of Malware Abusing LogMeIn and PDQ Connect
ID: 09c9dcb8-848b-5b63-b749-9c8ff468d8ae
STIX ID: report--09c9dcb8-848b-5b63-b749-9c8ff468d8ae
Feed Name: ASEC
AhnLab ASEC identified attacks in which threat actors used fake download pages to distribute installers for LogMeIn Resolve and PDQ Connect that register attacker-controlled CompanyId values; those RMM tools were then used to execute PowerShell and install PatoRAT, a Delphi backdoor with remote control, HVNC, keylogging and credential-theft capabilities. The report documents PatoRAT's 1-byte XOR RC_DATA "APPCONFIG" format, sample clientTags, supported commands, observed CompanyId values, MD5 hashes, malicious URLs/FQDNs, and advises validating download sources, certificates, and keeping systems and security products updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
