ATT&CKReferencesTalos PoetRAT October 2020

Talos PoetRAT October 2020

Mercer, W. Rascagneres, P. Ventura, V. (2020, October 6). PoetRAT: Malware targeting public and private sector in Azerbaijan evolves . Retrieved April 9, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwarePoetRAT

PoetRAT has `pyminifier` to obfuscate scripts.

T1041
Exfiltration Over C2 Channel
MalwarePoetRAT

PoetRAT has exfiltrated data over the C2 channel.

T1059.003
Windows Command Shell
MalwarePoetRAT

PoetRAT has called cmd through a Word document macro.

T1059.005
Visual Basic
MalwarePoetRAT

PoetRAT has used Word documents with VBScripts to execute malicious activities.

T1059.011
Lua
MalwarePoetRAT

PoetRAT has executed a Lua script through a Lua interpreter for Windows.

T1071.001
Web Protocols
MalwarePoetRAT

PoetRAT has used HTTP and HTTPs for C2 communications.

T1071.002
File Transfer Protocols
MalwarePoetRAT

PoetRAT has used FTP for C2 communications.

T1105
Ingress Tool Transfer
MalwarePoetRAT

PoetRAT has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS.

T1140
Deobfuscate/Decode Files or Information
MalwarePoetRAT

PoetRAT has used LZMA and base64 libraries to decode obfuscated scripts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.