RATatouille: Cooking Up Chaos in the I2P Kitchen
ID: 68ad7245-3429-50f9-8079-ac0edf9e8129
STIX ID: report--68ad7245-3429-50f9-8079-ac0edf9e8129
Feed Name: Sekoia.com
This FLINT report documents the discovery and reverse engineering of I2PRAT, a sophisticated multi-stage Windows RAT observed in a ClickFix delivery campaign (Nov 2024–Jan 2025). The analysis describes a packed first-stage loader that performs privilege checks and escalation (RPC abuse, SeDebug-based process migration/parent PID spoofing), dynamic API resolution, anti-debugging and string obfuscation, and a final modular RAT that communicates over the I2P network; the report provides IOCs (IPs, ports, filenames, registry/service changes), C2-hunting findings, Sigma/Suricata detection ideas, and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
