BreachRAT
Description
(FireEye) The payload is a backdoor that we call the Breach Remote Administration Tool (BreachRAT) written in C++. We had not previously observed this payload used by these threat actors. The malware name is derived from the hardcoded PDB path found in the RAT: C:\Work\Breach Remote Administration Tool\Release\Client.pdb. This RAT communicates with 5.189.145.248, a command and control (C2) IP address that this group has used previously with other malware, including DarkComet and njRAT.
Names
Name |
---|
BreachRAT |
Category
Malware
Type
- Backdoor
Information
Malpedia
Other Information
Uuid
807e9d0d-79f0-4da5-91c7-c8c073fc6782
Last Card Change
2020-04-23