RARSTONE

Description

(Trend Micro) The new sample detected by Trend Micro as BKDR_RARSTONE.A is similar (but not) PlugX, as it directly loads a backdoor “file” in memory without dropping any “file”. However, as we proceeded with our analysis, we found that BKDR_RARSTONE has some tricks of its own.

Names

Name
RARSTONE

Category

Malware

Type

  • Backdoor
  • Info stealer
  • Exfiltration

Information

Mitre Attack

Alienvault Otx

Other Information

Uuid

fd4b3d40-a16d-4451-bcc9-d620176310e1

Last Card Change

2020-06-13