Pcrat

Malware updated 5 months ago (2024-05-04T22:18:11.953Z)
Download STIX
Preview STIX
PCrat is a notorious remote administration trojan, with its source code openly accessible on the public internet. This malware, along with KimJongRAT, has been identified as part of malicious cyber attacks. In our analysis, we found that these two malwares were used as the encoded secondary payload in BabyShark attacks, earning them the nickname "Cowboys". Their primary function appears to be information stealing and disruption of operations. The original filename "cow_pass.fig" suggests that KimJongRAT is primarily used for password extraction, while PCRat supports data exfiltration to Command and Control (C2) servers. These malware families have shown their adaptability and potential for future use in different configurations. While the current focus is on PCRat and KimJongRAT, threat actors may shift to other malware families in the future. In this case, PCRat was observed communicating with a C2 server at IP address 173.248.170[.]149:80. This shows the malware's ability to establish a connection with external servers, further highlighting its threat potential. Despite the threats posed by PCRat and KimJongRAT, defenses against them are robust. Our Intrusion Prevention System (IPS) engine effectively blocks both pre and post infection network communications from the BabyShark and PCRat malware families. By decoding the PCRat payload metadata, we can gain insights into the operation of the malware, allowing us to better anticipate and counter future attacks.
Description last updated: 2024-05-04T21:41:29.884Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Pcrat Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more