NineRAT

Description

(Talos) Once the credential dumping is complete, Lazarus deploys a previously unknown RAT we’re calling “NineRAT” on the infected systems. NineRAT was first seen being used in the wild by Lazarus as early as March 2023. NineRAT is written in DLang and indicates a definitive shift in TTPs from APT groups falling under the Lazarus umbrella with the increased adoption of malware being authored using non-traditional frameworks such as the Qt framework, including MagicRAT and QuiteRAT.

Names

Name
NineRAT

Category

Malware

Type

  • Backdoor

Information

Malpedia

Other Information

Uuid

2e24f136-01b4-4a37-bcca-bf0cd84da24a

Last Card Change

2024-01-17