Poco RAT Burrows Deep Into Mining Sector
ID: 633a3170-a51c-580e-9efc-8b28a810815a
STIX ID: report--633a3170-a51c-580e-9efc-8b28a810815a
Feed Name: Dark Reading
Date Published: 2024-07-10
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Unidentified attackers are running a Spanish-language phishing campaign targeting primarily Latin American mining and manufacturing organizations to distribute Poco RAT, a Delphi-built credential-stealing remote access trojan that uses Google Drive-hosted 7zip payloads, POCO C++ libraries for evasion, persists via registry and launches grpconv.exe, communicates with a static C2 (94.131.119.126) on ports 6541–6543 and restricts responses to victims geolocated in Latin America; Cofense researchers provide IOCs and recommend blocking Google Drive links, monitoring grpconv.exe execution, and blocking the known C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
