logo

New I2PRAT Malware: Advanced, Undetectable?

ID: 5dafdbfc-b260-5523-b35a-bf5665704c7b

STIX ID: report--5dafdbfc-b260-5523-b35a-bf5665704c7b

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2025-02-14

Date Updated: 2026-04-22

Author: do son

...
...

Sekoia researchers report on I2PRAT, a sophisticated Remote Access Trojan observed since November 2024 as part of the ClickFix campaign that uses the I2P anonymization network for C2. The malware employs a three-stage chain (binder/packer → obfuscated loader → final RAT), advanced privilege escalation (parent PID spoofing, RPC-based UAC bypass attempts), dynamic API resolution, anti-debugging, AES-128-CBC communications with per-infection keys, and persistence via a stealth service named "RDP-Controller" while disabling Microsoft Defender and modifying the Windows Filtering Platform; recommended detection includes monitoring SeDebugPrivilege changes, suspicious registry/RDP modifications, and TCP connections to I2P nodes on ports 1110–1130.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.