[ << ALL_FEED ]

Evolution of Dark Caracal tools

More in General

Evolution of Dark Caracal Tools 🐱

In the first quarter of 2024, a malicious sample came to the attention of the Threat Intelligence department at the Positive Technologies Expert Security Center (PT ESC).

The target audience of the attack was Spanish-speaking users — this is evident from the content of the malicious attachments and the language of the phishing emails used to deliver the malware. The community named the malware Poco RAT — after the POCO C++ libraries used. At the time of discovery, the sample was not attributed to any known group.

🤨 Analysis of the sample revealed a specific set of functions for remote control of the victim’s device, including file upload, screenshot capture, command execution, and process and file management.

Additional analysis of tactics, techniques, and procedures, the attack chain, and campaign geography made it possible to link the activity to the Dark Caracal group, known for using the Bandook malware. Similarities were also identified between the Poco RAT and Bandook droppers.

You can read more about Dark Caracal, its methods, and new tools in the research on our website 👽

#TI #APT #malware
@ptescalator

More from ti_author

More from ti_author

More in General