Deed Rat

Malware updated a year ago (2024-11-29T13:57:58.617Z)
Download STIX
Preview STIX
Deed RAT is a sophisticated malware associated with the Space Pirates group, known for its ability to encapsulate its protocol in HTTP, HTTPS, and DNS. It stores all its data, including configuration and plugins, in the system registry and collects information about in-use proxies through network sniffing. Notably, Deed RAT can detect and use a proxy to connect to its Command and Control (C2) server. The control server, ftp.microft.dynssl.com, is directly linked to the infrastructure of the Space Pirates group, indicating a significant threat level posed by this malware. The Space Pirates toolkit features unique downloaders and several previously unencountered backdoors, presumably specific to the group. These include MyKLoadClient, BH_A006, and Deed RAT. An additional tool in their arsenal is Masol RAT, a cross-platform tool used against Linux servers from Southeast Asian governments. Also noteworthy is SnappyBee, also known as Deed RAT, a modular backdoor that is considered the successor to ShadowPad. This malware was previously revealed by Postiv Technologies and is primarily executed through DLL sideloading. Lateral movement within infected networks is performed by the initial backdoor, with additional backdoors such as Zingdoor and SnappyBee (Deed RAT) being installed on other machines within the network. Deed RAT is also capable of gathering the language code identifier (LCID) during system information collection, adding another layer of complexity to its operations. The observed IP addresses associated with Deed RAT are 45.76.145.22, 103.27.109.234, and 108.160.134.113. The combination of these advanced capabilities makes Deed RAT a potent threat to cybersecurity, requiring robust countermeasures.
Description last updated: 2024-11-28T11:53:01.552Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Snappybee is a possible alias for Deed Rat. Snappybee, also known as Deed RAT, is a modular backdoor malware that has been identified as part of the toolkit used by Earth Estries to exploit target machines. It is one of four major tools, including Cobalt Strike and Zingdoor, used by the group to gain control over systems. Snappybee is often d
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Backdoor
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Deed Rat Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more