logo

RATatouille: Cooking Up Chaos in the I2P Kitchen

ID: f6ff5b33-6998-52be-8ac4-dfca90e9b973

STIX ID: report--f6ff5b33-6998-52be-8ac4-dfca90e9b973

Feed Name: Sekoia.io Blog

Threat Score
75/100

Date Published: 2025-02-11

Date Updated: 2026-04-29

Author: Pierre Le Bourhis

...
...

This FLINT report analyzes I2PRAT, a sophisticated multi-stage Remote Access Trojan observed in the ClickFix campaign (Nov 2024–Jan 2025). The report details the loader's privilege checks and escalation (RPC abuse, SeDebug and parent PID spoofing), anti-debugging and string obfuscation, dynamic API resolution, encrypted TCP/I2P C2 communication, installation artifacts (dropped DLLs, service persistence), and provides IOCs and detection rules for network, registry and file-based telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.