logo

China-linked APT17 Targets Italian Companies with 9002 RAT Malware

ID: 61fad58c-f016-5b11-a329-112fc0f26baa

STIX ID: report--61fad58c-f016-5b11-a329-112fc0f26baa

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-07-17

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

A China-linked APT17 conducted targeted spear-phishing campaigns against Italian companies and government entities in June–July 2024, using an MSI installer named "SkypeMeeting.msi" that runs a JAR via VBS to decrypt and execute shellcode that launches the modular 9002 RAT (Hydraq/McRAT). The malware provides network monitoring, screenshots, file enumeration, process management, and remote command execution, with the actor employing diskless variants and modular activation to evade interception.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.