logo

New Poco RAT Targets Spanish-Speaking Victims in Phishing Campaign

ID: cc71bd67-eb62-5ede-9df3-8db820337a91

STIX ID: report--cc71bd67-eb62-5ede-9df3-8db820337a91

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-07-11

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Spanish-language phishing campaigns have been observed delivering a new Delphi-based remote access trojan called Poco RAT since February 2024; attacks use finance-themed emails that link to Google Drive-hosted 7-Zip archives or embedded HTML/PDF files, establish persistence on Windows hosts, and contact geofenced C2 servers to fetch additional payloads. The malware emphasizes anti-analysis and C2 communications and is part of a broader trend of abusing legitimate services (Google Drive, PDFs/QRs) and social-engineering lures to distribute RATs and information-stealing tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.