Skip to content

RAT

9002 RAT

aka McRAT · Hydraq · HOMEUNIX

9002 RAT is a Remote Access Tool typically observed to be used by an APT to control a victim's machine.

9002 RAT is a Remote Access Tool typically observed to be used by an APT to control a victim's machine. It has been spread over via zero day exploits (e.g. targeting Internet Explorer) as well as via email attachments. The infection chain starts by opening a .LNK (an OLE packager shell object) that executes a Powershell command.


Family metadata imported from Malpedia (Fraunhofer FKIE).