BreachRAT

Description

(FireEye) The payload is a backdoor that we call the Breach Remote Administration Tool (BreachRAT) written in C++. We had not previously observed this payload used by these threat actors. The malware name is derived from the hardcoded PDB path found in the RAT: C:\Work\Breach Remote Administration Tool\Release\Client.pdb. This RAT communicates with 5.189.145.248, a command and control (C2) IP address that this group has used previously with other malware, including DarkComet and njRAT.

Names

Name
BreachRAT

Category

Malware

Type

  • Backdoor

Information

Malpedia

Other Information

Uuid

807e9d0d-79f0-4da5-91c7-c8c073fc6782

Last Card Change

2020-04-23