logo

DeedRAT Backdoor Enhanced by Chinese APTs with Advanced Capabilities

ID: 20fc8d23-8640-5eb1-bf55-af28bbda387d

STIX ID: report--20fc8d23-8640-5eb1-bf55-af28bbda387d

Feed Name: Lab52 Blog

Threat Score
75/100

Date Published: 2025-07-18

Date Updated: 2026-04-28

Author: 3722304989

...
...

LAB52 (S2 Group) reports a phishing campaign delivering the DeedRAT modular backdoor by abusing a signed VIPRE antivirus binary (MambaSafeModeUI.exe / MicRun.exe) via DLL side-loading; the loader decrypts and executes encrypted shellcode in memory, establishes persistence (service and Run registry key), communicates with a C2 (luckybear669.kozow.com) over TCP/80/443, and includes a newly observed NetAgent module. The analysis includes detailed artifacts and IOCs (file hashes, paths, mutex, registry key, and C2) and notes low detection on VirusTotal and increased loader obfuscation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.