Moonrise RAT: A New Low-Detection Threat with High-Cost Consequences
ID: d279bd4f-c4dc-5781-8441-3573e3d05a4a
STIX ID: report--d279bd4f-c4dc-5781-8441-3573e3d05a4a
Feed Name: ANY.RUN's Cybersecurity Blog
This report analyzes Moonrise, a stealthy Go-based RAT that initially bypassed static detection and rapidly established WebSocket C2 connectivity; it documents observed commands and capabilities (process/file enumeration, remote execution, credential/clipboard theft, screen/webcam/audio capture, persistence and lifecycle management), provides multiple sample hashes and a C2 IP, and recommends behavior-based monitoring, sandbox execution, and TI-enrichment for earlier detection and containment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
