SwaetRAT Delivery Through Python, (Fri, Jan 3rd)

SANS Internet Storm Center, InfoCON: green 2025-01-03

Summary:

We entered a new year, but attack scenarios have not changed (yet). I found a Python script with an interesting behavior[1] and a low Virustotal score (7/61). It targets Microsoft Windows hosts because it starts by loading all libraries required to call Microsoft API Calls and manipulate payloads:

Link:

https://isc.sans.edu/diary/rss/31554

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

01/03/2025, 11:23

Date published:

01/03/2025, 01:41