logo

Poco RAT Burrows Deep Into Mining Sector

ID: 633a3170-a51c-580e-9efc-8b28a810815a

STIX ID: report--633a3170-a51c-580e-9efc-8b28a810815a

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-07-10

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Unidentified attackers are running a Spanish-language phishing campaign targeting primarily Latin American mining and manufacturing organizations to distribute Poco RAT, a Delphi-built credential-stealing remote access trojan that uses Google Drive-hosted 7zip payloads, POCO C++ libraries for evasion, persists via registry and launches grpconv.exe, communicates with a static C2 (94.131.119.126) on ports 6541–6543 and restricts responses to victims geolocated in Latin America; Cofense researchers provide IOCs and recommend blocking Google Drive links, monitoring grpconv.exe execution, and blocking the known C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.