logo

U.S. DoJ Dismantles Warzone RAT Infrastructure, Arrests Key Operators

ID: 083f05a6-9cdd-57e7-b6fc-b20761b5250a

STIX ID: report--083f05a6-9cdd-57e7-b6fc-b20761b5250a

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The U.S. Department of Justice, with international partners, seized domains and infrastructure used to sell Warzone RAT (Ave Maria) and arrested two individuals accused of selling and supporting the RAT; the malware—distributed as a MaaS—functions as an information stealer and remote access trojan with capabilities including file system browsing, screenshots, keylogging, credential theft, and webcam activation, and has been delivered via phishing (including exploits of CVE-2017-11882) and used by other criminal and advanced actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.