logo

DRAT V2: Updated DRAT Emerges in TAG-140’s Arsenal

ID: b33338c7-04a2-591e-9bd5-c344b5d22dfe

STIX ID: report--b33338c7-04a2-591e-9bd5-c344b5d22dfe

Feed Name: Recorded Future Blog

Threat Score
85/100

Date Published: 2025-06-19

Date Updated: 2026-04-28

...
...

Insikt Group identified a TAG-140 (APT36/SideCopy) campaign that used a cloned Indian Ministry of Defence press-release site and a ClickFix-style mshta lure to deliver a BroaderAspect loader which installs a new Delphi-based DRAT V2 RAT; the report documents DRAT V2’s server-initiated TCP C2 protocol, command set (including arbitrary shell execution), C2 obfuscation techniques, IOCs (hashes, domains, and C2 IPs), detection signatures (Snort, Sigma, YARA), and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.