RATANKBA

RATANKBARatankba

Description

In one instance we observed, one of the initial malware delivered to the victim, RATANKBA, connects to a legitimate but compromised website from which a hack tool (nbt_scan.exe) is also downloaded. The domain also serves as one of the campaign’s platform for C&C communication. The threat actor uses RATANKBA to survey the lay of the land as it looks into various aspects of the host machine where it has been initially downloaded—the machine that has been victim of the watering hole attack. Information such as the running tasks, domain, shares, user information, if the host has default internet connectivity, and so forth.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
PowerRatankba
Software
Rurktar
Software
GovRAT
Software
RadRAT
Software
AtlasAgent
Software
Ragnatela
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.