Hijacking the Hackers: Researchers Sinkhole “KazakRAT” Espionage Campaign
ID: 36d404d4-28b1-50e9-baf0-8692428964c4
STIX ID: report--36d404d4-28b1-50e9-baf0-8692428964c4
Feed Name: securityonline.info
KazakRAT is a minimally obfuscated Windows DLL-based Remote Access Trojan discovered by researchers that has been used since at least August 2022 to target Kazakh and Afghan government and financial entities via malicious MSI installers and decoy documents; unencrypted HTTP C2 beaconing and a lapsed domain (dns.freiesasien.com) were sinkholed to confirm victim IPs and regional targeting in Karaganda, and analysts note tooling overlap with APT36 though attribution is not definitive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
