Blog | G5 Cyber Security

Unpacking the Kwampirs RAT

The FBI recently issued a public warning about a malware campaign targeting supply chain software providers. The FBI has also been warned about a threat from the Orangeworm group. The most important part of this malware is its configuration (control servers, mutex it uses, registry keys it creates), since it’s essentially a remote access trojan (RAT) The main RAT functionality can be found in the DLL payload of the installer. The Retro Hunt feature offers a quick way to match those YARA rules against all samples seen by the ReversingLabs A1000 threat analysis platform.”]

Source: https://blog.reversinglabs.com/blog/unpacking-kwampirs-rat

Exit mobile version