logo

MINEBRIDGE Remote-access Trojan (RAT) 2021

ID: 403450d6-dd84-572d-97f1-0eb3abf29fef

STIX ID: report--403450d6-dd84-572d-97f1-0eb3abf29fef

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Zscaler ThreatLabZ describes a TA505-linked campaign deploying the MINEBRIDGE RAT via macro-laden Word resume lures that use LOLBins and TeamViewer DLL side-loading to gain persistence, hook APIs, exfiltrate TeamViewer credentials and system information, and communicate with hardcoded C2 domains; the report includes detailed TTP mapping and comprehensive IOCs (hashes, filenames, domains, network paths).**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.