SparkRAT: A Persistent Cross-Platform Cyber Threat Targeting macOS and Beyond
ID: f9568c74-fc1f-5d3c-b5e9-a34a087c10c4
STIX ID: report--f9568c74-fc1f-5d3c-b5e9-a34a087c10c4
Feed Name: securityonline.info
Threat Score
**Executive Summary:** SparkRAT is a Golang-based, modular, cross-platform remote access trojan actively used in post-exploitation campaigns (including exploitation of CVE-2024-27198) with evidence of suspected DPRK-linked espionage; Hunt.io identified multiple active C2 servers, payloads (including macOS Mach-O and an Android APK), persistence mechanisms, WebSocket/HTTP C2 behaviors, and concrete IOCs (IPs, ports, SHA-256s) that enable detection and tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
