Threat Advisory

New stealthy Python RAT malware targets Windows in attacks

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary: 

Researchers recently spotted a new python-based malware named PY#RATION a remote access trojan (RAT), which gives its operators control over breached systems. PY#RATION uses WebSocket protocol to communicate with the command and control (C2) server and to exfiltrate data from the victim host. The distribution of the malware is done via a phishing campaign that uses password-protected ZIP file containing two shortcut .LNK files disguise as images.[/subscribe_to_unlock_form]

Summary: 

Researchers recently spotted a new python-based malware named PY#RATION a remote access trojan (RAT), which gives its operators control over breached systems. PY#RATION uses WebSocket protocol to communicate with the command and control (C2) server and to exfiltrate data from the victim host. The distribution of the malware is done via a phishing campaign that uses password-protected ZIP file containing two shortcut .LNK files disguise as images.[emaillocker id="1283"]

Threat Profile: 

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/new-stealthy-python-rat-malware-targets-windows-in-attacks/

[/emaillocker]
crossmenu