Poolrat

Malware updated 4 months ago (2024-05-04T20:38:21.785Z)
Download STIX
Preview STIX
PoolRat, a harmful malware previously classified as SimpleSea by threat intelligence firms, is designed to exploit and damage computer systems. This C/C++ macOS implant has the capability of collecting basic system information and executing arbitrary commands, including carrying out file operations. The malware infects systems through suspicious downloads, emails, or websites, often without the user's knowledge. Once inside, it can steal personal information, disrupt operations, or even hold data hostage for ransom. The macOS build server was compromised using PoolRat as a backdoor, with LaunchDaemons serving as a persistence mechanism. This incident occurred alongside attacks involving other malware families such as TaxHaul, ColdCat, and IconicStealer, as tracked by Mandiant. Detailed descriptions of these malware programs were provided in an initial findings report published on April 11th by 3CX, the company that discovered the breach. A link between PoolRat and AppleJeus has been established due to the threat actor's previous use of an older version of PoolRat in a long-running campaign. This campaign, documented by CISA in an advisory in 2021, disseminated booby-trapped trading applications like CoinGoTrade to facilitate cryptocurrency theft. This evidence suggests that PoolRat is part of a broader cyberthreat landscape involving sophisticated trojanized applications and persistent threats.
Description last updated: 2024-05-04T17:28:33.462Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Poolrat Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago
3CX hack highlights risk of cascading software supply-chain compromises
CERT-EU
a year ago
Cascading Supply Chain Attack: 3CX Hacked After Employee Downloaded Trojanized App
CERT-EU
a year ago
3CX breach linked to previous supply chain compromise
CERT-EU
a year ago
N.K. Hackers Employ Matryoshka Doll-Style Cascading Supply Chain Attack on 3CX
CERT-EU
a year ago
N.K. Hackers Employ Matryoshka Doll-Style Cascading Supply Chain Attack on 3CX
CERT-EU
a year ago
The 3CX attack gets wilder, marks first 'cascading software supply chain compromise'
CERT-EU
a year ago
Infected app on employee’s PC led to 3CX compromise: Report | IT World Canada News
CERT-EU
a year ago
An earlier supply chain attack led to the 3CX supply chain attack, Mandiant says • The Register | #cybercrime | #infosec – National Cyber Security Consulting