U.S. DoJ Dismantles Warzone RAT Infrastructure, Arrests Key Operators
ID: 083f05a6-9cdd-57e7-b6fc-b20761b5250a
STIX ID: report--083f05a6-9cdd-57e7-b6fc-b20761b5250a
Feed Name: The Hacker News
The U.S. Department of Justice, with international partners, seized domains and infrastructure used to sell Warzone RAT (Ave Maria) and arrested two individuals accused of selling and supporting the RAT; the malware—distributed as a MaaS—functions as an information stealer and remote access trojan with capabilities including file system browsing, screenshots, keylogging, credential theft, and webcam activation, and has been delivered via phishing (including exploits of CVE-2017-11882) and used by other criminal and advanced actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
