Magicrat

Malware updated 6 months ago (2024-05-04T20:21:14.839Z)
Download STIX
Preview STIX
MagicRAT is a type of malware, first observed by Cisco Talos in 2022, that was used by the Lazarus Group to exploit vulnerabilities in publicly exposed VMWare Horizon platforms, primarily targeting energy companies worldwide. This malicious software, which can infiltrate systems through suspicious downloads, emails, or websites, can steal personal information, disrupt operations, and even hold data hostage for ransom. The Lazarus group, known for its use of custom malware, has been linked to both MagicRAT and its derivative, QuiteRAT. In May 2023, the Lazarus Group began deploying QuiteRAT, a smaller, more compact Qt-based implant that's clearly an evolution of MagicRAT. North Korean coders managed to reduce the size of this Trojan to 5 megabytes from MagicRAT's original 18MB by incorporating only a handful of required Qt libraries instead of the entire framework. Both Trojans are based on the Qt open-source development framework, which makes machine learning and heuristic analysis detection tools less reliable since Qt is rarely used in malware development. The campaign introduced several new malware families such as YamaBot and MagicRat, along with updated versions of NukeSped and DTrack. Significant similarities were also found between EarlyRAT and Lazarus' MagicRAT tool, indicating a potential shift in tactics and possible involvement of inexperienced operators. The use of non-traditional frameworks like Qt in malware authoring, as seen in MagicRAT and QuiteRAT, represents a definitive shift in techniques, tactics, and procedures (TTPs) from APT groups under the Lazarus umbrella.
Description last updated: 2024-05-04T16:47:21.007Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Quiterat is a possible alias for Magicrat. QuiteRAT is a new type of malware associated with the North Korea-linked Lazarus Group, known for their use of custom malware. Built using the Qt framework, QuiteRAT is smaller in size compared to MagicRAT, another malware linked to the group, due to its incorporation of fewer Qt libraries and lack
4
Earlyrat is a possible alias for Magicrat. EarlyRat is a previously undocumented malware discovered by Kaspersky researchers in June. The North Korea-linked Advanced Persistent Threat (APT) group Andariel used EarlyRat in attacks exploiting the Log4j Log4Shell vulnerability last year. The malware was first noticed in one of the Log4j cases,
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Trojan
Apt
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The Lazarus Group Threat Actor is associated with Magicrat. The Lazarus Group, a notorious threat actor linked to North Korea, is among the most prolific and dangerous cyber threat actors in operation. They have been involved in numerous cyber-attacks worldwide, with significant efforts put into their social engineering strategies. Their activities include eUnspecified
4
Source Document References
Information about the Magicrat Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
BankInfoSecurity
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
BankInfoSecurity
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Securityaffairs
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago