logo

Tracking an evolving Discord-based RAT family

ID: f5172818-08b8-5d4e-83f1-471b552abe70

STIX ID: report--f5172818-08b8-5d4e-83f1-471b552abe70

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2025-10-29

Date Updated: 2026-04-29

Author: Robert Simmons

...
...

ReversingLabs identified four closely related Discord-based remote access trojans (UwUdisRAT, STD RAT, Minecraft RAT, and Propionanilide RAT) attributed to the actor calling themselves "STD Group." The report details compilation timestamps, obfuscation (ROT23, stack strings, decoys), a custom packer (Proplock/STD Crypter using XZ/LZMA2 and XOR), shared mutexes and other TTPs, and provides extensive IOCs (many file hashes), a Python ROT-23 decryptor, and YARA rules to detect both packed and payload samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.