Skip to content

Malware

Ratankba

aka QUICKRIDE

This is a backdoor that establishes persistence using the Startup folder.

Ratankba, also known as QUICKRIDE, is a Windows malware family operated by Lazarus Group.

Background

This backdoor maintains persistence through the Startup folder and reaches its C&C server over HTTPS using a fixed HTTP User-Agent string. QUICKRIDE can collect system information, fetch and load executables, and remove itself. It was used in attacks against banks in Poland.


Source: Malpedia (Fraunhofer FKIE).