RedLeaves

Description

(US-CERT) The REDLEAVES implant consists of three parts: an executable, a loader, and the implant shellcode. The REDLEAVES implant is a remote administration Trojan (RAT) that is built in Visual C++ and makes heavy use of thread generation during its execution. The implant contains a number of functions typical of RATs, including system enumeration and creating a remote shell back to the C2.

Names

Name
RedLeaves
BUGJUICE

Category

Malware

Type

  • Reconnaissance
  • Backdoor

Information

Mitre Attack

Malpedia

Alienvault Otx

Other Information

Uuid

30de5fb0-f7b6-4795-9732-e90515d91451

Last Card Change

2020-05-14