logo

GoodPersonRAT: Fake Chinese VPN drops extensive C2 client

ID: b8f40ff3-79fa-5a02-b095-5f16ed86a134

STIX ID: report--b8f40ff3-79fa-5a02-b095-5f16ed86a134

Feed Name: ThreatLocker Blog

Threat Score
82/100

Date Published: 2026-07-08

Date Updated: 2026-07-19

...
...

#### Executive summary ThreatLocker analyzed a malicious MSI that bundles a legitimate LetsVPN installer with a hidden shellcode loader and a reflectively loaded RAT, enabling persistent full remote control, keylogging, browser/Telegram data exfiltration and proxy manipulation. The report details loader/payload behavior, C2 selection, persistence mechanisms, EDR/Defender tampering, AutoUpdate functionality, provides indicators (IPs, domains, SHA-256 hashes, file paths), and recommends allowlisting, ringfencing, and web content controls to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.