Evolution of Dark Caracal tools

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Evolution of Dark Caracal Tools 🐱
In the first quarter of 2024, a malicious sample came to the attention of the Threat Intelligence department at the Positive Technologies Expert Security Center (PT ESC).
The target audience of the attack was Spanish-speaking users — this is evident from the content of the malicious attachments and the language of the phishing emails used to deliver the malware. The community named the malware Poco RAT — after the POCO C++ libraries used. At the time of discovery, the sample was not attributed to any known group.
🤨 Analysis of the sample revealed a specific set of functions for remote control of the victim’s device, including file upload, screenshot capture, command execution, and process and file management.
Additional analysis of tactics, techniques, and procedures, the attack chain, and campaign geography made it possible to link the activity to the Dark Caracal group, known for using the Bandook malware. Similarities were also identified between the Poco RAT and Bandook droppers.
You can read more about Dark Caracal, its methods, and new tools in the research on our website 👽
#TI #APT #malware
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



