RATatouille: Cooking Up Chaos in the I2P Kitchen
ID: f6ff5b33-6998-52be-8ac4-dfca90e9b973
STIX ID: report--f6ff5b33-6998-52be-8ac4-dfca90e9b973
Feed Name: Sekoia.io Blog
This FLINT report analyzes I2PRAT, a sophisticated multi-stage Remote Access Trojan observed in the ClickFix campaign (Nov 2024–Jan 2025). The report details the loader's privilege checks and escalation (RPC abuse, SeDebug and parent PID spoofing), anti-debugging and string obfuscation, dynamic API resolution, encrypted TCP/I2P C2 communication, installation artifacts (dropped DLLs, service persistence), and provides IOCs and detection rules for network, registry and file-based telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
