GoodPersonRAT: Fake Chinese VPN drops extensive C2 client
ID: b8f40ff3-79fa-5a02-b095-5f16ed86a134
STIX ID: report--b8f40ff3-79fa-5a02-b095-5f16ed86a134
Feed Name: ThreatLocker Blog
#### Executive summary ThreatLocker analyzed a malicious MSI that bundles a legitimate LetsVPN installer with a hidden shellcode loader and a reflectively loaded RAT, enabling persistent full remote control, keylogging, browser/Telegram data exfiltration and proxy manipulation. The report details loader/payload behavior, C2 selection, persistence mechanisms, EDR/Defender tampering, AutoUpdate functionality, provides indicators (IPs, domains, SHA-256 hashes, file paths), and recommends allowlisting, ringfencing, and web content controls to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
