Skip to content

Malware

FlawedGrace

aka GraceWire

According to ProofPoint, FlawedGrace is written in C++ and can be categorized as a Remote Access Trojan (RAT).

FlawedGrace, also known as GraceWire, is a Windows malware family operated by TA505.

Background

ProofPoint reports that FlawedGrace is a C++ Remote Access Trojan (RAT), apparently developed primarily during the latter half of 2017.

FlawedGrace supports a set of commands, listed below for reference:

  • desktop_stat
  • destroy_os
  • target_download
  • target_module_load
  • target_module_load_external
  • target_module_unload
  • target_passwords
  • target_rdp
  • target_reboot
  • target_remove
  • target_script
  • target_servers
  • target_update
  • target_upload

Source: Malpedia (Fraunhofer FKIE).