RAT
BalkanRAT
The goal of BalkanRAT which is a more complex part of the malicious Balkan-toolset (cf.
BalkanRAT is a Windows rat.
Background
BalkanRAT, the more sophisticated half of the malicious Balkan toolset (alongside BalkanDoor), is designed to install and abuse legitimate commercial remote-administration software. It bundles several supplementary components that load and install the remote desktop tool while hiding its presence. A long-running BalkanRAT campaign has been active since at least January 2016, focusing on the accounting departments of organizations in Croatia, Serbia, Montenegro, and Bosnia and Herzegovina, with the emails, links, and decoy PDFs all built around tax themes. The malware was validly signed and was deployed by exploiting the WinRAR ACE vulnerability (CVE-2018-20250).
Source: Malpedia (Fraunhofer FKIE).