logo

Java-Based SAW RAT's Infiltration Via LNK Files Uncovered

ID: dad336c0-1894-543d-87ec-38ee488cc56a

STIX ID: report--dad336c0-1894-543d-87ec-38ee488cc56a

Feed Name: Cyble Blog

Threat Score
60/100

Date Published: 2026-07-02

Date Updated: 2026-07-16

...
...

Cyble Research found a malicious ZIP archive containing an LNK shortcut and a Java Runtime Environment directory that drops a decoy PDF and a 14 KB malicious JAR ("Saw RAT"). The Java RAT establishes a socket-based C2 connection (144.91.112.130:6023), supports system information collection, file transfer, directory listing, command execution, and screenshot capture, and is likely distributed via spam with a password-protected lure PDF. The report includes IOCs (file hashes, LNK name, and C2) and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.