RAT
9002 RAT
aka McRAT · Hydraq · HOMEUNIX
9002 RAT is a Remote Access Tool typically observed to be used by an APT to control a victim's machine.
9002 RAT is a Remote Access Tool typically observed to be used by an APT to control a victim's machine. It has been spread over via zero day exploits (e.g. targeting Internet Explorer) as well as via email attachments. The infection chain starts by opening a .LNK (an OLE packager shell object) that executes a Powershell command.
Family metadata imported from Malpedia (Fraunhofer FKIE).