logo

Hunters International Disguises SharpRhino RAT as Legitimate Network Admin Tool

ID: c8459165-60c5-5200-91d5-0575b3c96d0c

STIX ID: report--c8459165-60c5-5200-91d5-0575b3c96d0c

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-08-06

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers from Quorum Cyber identified SharpRhino, a novel RAT used by Hunters International to masquerade as Angry IP Scanner, establish persistence (registry Run key and ProgramData directories), and enable deployment of Hive ransomware; the group leverages RaaS, abused code-signing certificates, and opportunistic targeting, with indicators of compromise and MITRE ATT&CK mappings provided to help defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.