RARSTONE
Description
(Trend Micro) The new sample detected by Trend Micro as BKDR_RARSTONE.A is similar (but not) PlugX, as it directly loads a backdoor “file” in memory without dropping any “file”. However, as we proceeded with our analysis, we found that BKDR_RARSTONE has some tricks of its own.
Names
Name |
---|
RARSTONE |
Category
Malware
Type
- Backdoor
- Info stealer
- Exfiltration
Information
Mitre Attack
Alienvault Otx
Other Information
Uuid
fd4b3d40-a16d-4451-bcc9-d620176310e1
Last Card Change
2020-06-13