UBOATRAT

UBOATRATUBoatRAT

Description

Alto Networks Unit 42 has identified attacks with a new custom Remote Access Trojan (RAT) called UBoatRAT. The initial version of the RAT, found in May of 2017, was simple HTTP backdoor that uses a public blog service in Hong Kong and a compromised web server in Japan for command and control. The developer soon added various new features to the code and released an updated version in June. The attacks with the latest variants we found in September have following characteristics. Targets personnel or organizations related to South Korea or video games industry Distributes malware through Google Drive Obtains C2 address from GitHub Uses Microsoft Windows Background Intelligent Transfer Service(BITS) to maintain persistence.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
ROKRAT
Software
NavRAT
Software
htpRAT
Software
OceanSalt
Actor
UAT-5918
Software
RATAttack
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.