DRIVESILKRAT

DRIVESILKRATDriveSilkRAT

Description

DriveSilkRAT is a remote access trojan used by the SilkParasite activity cluster, observed by Bitdefender in Central Asia. Two lineages exist: an original .NET implementation and a later C++ rewrite. Its distinguishing trait is command and control over Google Drive, which places the traffic inside a service most networks already allow and cannot easily distinguish from legitimate use. Delivery relies on DLL sideloading through renamed legitimate binaries.
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.