New Data-Stealing Poco RAT Campaign Targeting Spanish Speakers
ID: bf782b12-00b5-5728-a96a-eb6d47228b12
STIX ID: report--bf782b12-00b5-5728-a96a-eb6d47228b12
Feed Name: HackRead
Threat Score
A new email-based campaign distributes Poco RAT to Spanish-speaking victims by hiding malware in Google Drive-hosted archives and documents disguised as financial files; the RAT persists on infected hosts, injects into legitimate processes, communicates with a C2 ("94131119126" on ports 6541–6543), and has primarily targeted the mining sector while capable of stealing data or delivering additional malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
