Hunters International Disguises SharpRhino RAT as Legitimate Network Admin Tool
ID: c8459165-60c5-5200-91d5-0575b3c96d0c
STIX ID: report--c8459165-60c5-5200-91d5-0575b3c96d0c
Feed Name: Dark Reading
Date Published: 2024-08-06
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers from Quorum Cyber identified SharpRhino, a novel RAT used by Hunters International to masquerade as Angry IP Scanner, establish persistence (registry Run key and ProgramData directories), and enable deployment of Hive ransomware; the group leverages RaaS, abused code-signing certificates, and opportunistic targeting, with indicators of compromise and MITRE ATT&CK mappings provided to help defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
