Ragnatela
Description
(Malwarebytes) We identified what we believe is a new variant of the BADNEWS RAT called Ragnatela being distributed via spear phishing emails to targets of interest in Pakistan. Ragnatela, which means spider web in Italian, is also the project name and panel used by Patchwork APT.
Ragnatela RAT was built sometime in late November as seen in its Program Database (PDB) path “E:\new_ops\jlitest __change_ops -29no – Copy\Release\jlitest.pdb”. It features the following capabilities: • Executing commands via cmd • Capturing screenshots • Logging Keystrokes • Collecting list of all the files in victim’s machine • Collecting list of the running applications in the victim’s machine at a specific time periods • Downing addition payloads • Uploading files
Names
Name |
---|
Ragnatela |
Ragnatela RAT |
Category
Malware
Type
- Backdoor
- Info stealer
- Keylogger
- Downloader
- Exfiltration
Information
Other Information
Uuid
2e9285ec-5ef6-4191-b13a-7c871bfb6e9f
Last Card Change
2022-01-25