logo

DeedRAT: Unpacking a Modern Backdoor’s Playbook

ID: 96df4867-903e-5ab9-ac4d-2ce33aae7ae3

STIX ID: report--96df4867-903e-5ab9-ac4d-2ce33aae7ae3

Feed Name: Binary Defense Blog

Threat Score
85/100

Date Published: 2025-12-30

Date Updated: 2026-04-27

...
...

Binary Defense ARC Labs analyzed DeedRAT, a stealthy backdoor attributed to the Salt Typhoon (Earth Estries) APT, showing a phishing-delivered ZIP that contains MicRun.exe, SBAMRES.dll, and SBAMRES.DLL.CC; the attack uses DLL sideloading to execute encrypted shellcode, persists by copying files to C:\ProgramData\MicroDefaults, and enables reconnaissance, file modification, and remote payload execution against government, telecom, and other critical sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.