'Bitter' cyberspies target defense orgs with new MiyaRAT malware
ID: 5ca0fb24-07c9-5dfa-8103-c8ca4805da2e
STIX ID: report--5ca0fb24-07c9-5dfa-8103-c8ca4805da2e
Feed Name: Bleeping Computer
Threat Score
Proofpoint observed the APT group Bitter targeting Turkish defense organizations with a new RAT family (MiyaRAT) used alongside WmRAT; the attackers delivered a RAR containing a decoy PDF, an LNK file, and alternate data streams that execute PowerShell, create a scheduled task to call a staging domain (jacknwoods.com), and fetch additional payloads, with IoCs and a YARA rule provided for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
