Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
awesome-rat — RAT- und C&C-Ressourcen. 250+ Open-Source-Projekte, 1200+ RAT/C&C-Blogs/Videos. | Kitploit
Tools/GitHubGitHub/alphaseclab/awesome-rat
Post-ExploitationMalware-AnalysePenetrationstestsCommand and ControlPapers & ForschungLernen & BildungRed TeamingKuratierte RessourcenRemote-Access-Tool
GitHubalphaseclab/awesome-rat

awesome-rat

RAT- und C&C-Ressourcen. 250+ Open-Source-Projekte, 1200+ RAT/C&C-Blogs/Videos.

2.2k47726vor 6 JahrenVon Kitploit geprüft
Repository anzeigen

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

Alle Sammlungsprojekte

RAT

  • 250+ Open-Source-RAT/C&C-Tools, 1200+ RAT-Analyseberichte/C&C-bezogene Artikel usw.
  • English Version

Inhaltsverzeichnis

  • Open-Source-Tools
    • pupy -> (1) Werkzeug (6) Artikel
    • Covenant -> (3) Werkzeuge (18) Artikel
    • Slackor -> (1) Werkzeug (3) Artikel
    • QuasarRAT -> (1) Werkzeug (9) Artikel
    • EvilOSX -> (1) Werkzeug (9) Artikel
    • Merlin -> (1) Werkzeug (3) Artikel
  • Kommerzielle Software
    • Team Viewer -> (7) Werkzeuge (34) Artikel
  • Schadsoftware (teilweise)
    • Gh0st -> (5) Werkzeuge (23) Artikel
    • NanoCore -> (1) Werkzeug (32) Artikel
    • NjRat -> (4) Werkzeuge (20) Artikel
    • Revenge RAT -> (1) Werkzeug (9) Artikel
    • PlugX -> (1) Werkzeug (40) Artikel
    • (25) RemcosRAT
    • (3) L0rdixRAT
    • (1) LodaRAT
    • (9) GulfRAT
    • (14) NetWireRAT
    • (1) JhoneRAT
    • (2) Dacls
    • (1) BlackRemote
    • (17) Orcus
    • (1) NukeSped
    • (21) DarkComet
    • (1) WarZone RAT
    • (16) BlackShades
    • (1) DenesRAT
    • (4) WSH RAT
    • (2) Qrypter RAT
    • (20) Adwind
    • (1) CannibalRAT
    • (3) jRAT
    • (5) jsRAT
    • (4) CrossRat
    • (1) ArmaRat
    • (6) RokRAT
    • (1) CatKARAT
    • (5) TheFatRat
    • (2) OmniRAT
    • (6) LuminosityLink
    • (477) Sonstige
  • Nutzung öffentlicher Dienste
    • Telegram -> (3) Werkzeuge (2) Artikel
    • Twitter -> (2) Werkzeuge (6) Artikel
    • GMail -> (3) Werkzeuge (8) Artikel
    • Github -> (1) Werkzeug (5) Artikel
    • DropBox -> (1) Werkzeug (3) Artikel
    • Blockchain -> (2) Werkzeuge (1) Artikel
    • Sonstige -> (15) Werkzeuge (5) Artikel
  • Kommunikationsprotokolle
    • DNS-Protokoll
      • (9) Werkzeuge
      • (18) Artikel
      • Domain Generation Algorithm (DGA) -> (14) Werkzeuge (42) Artikel
    • ICMP -> (5) Artikel
    • WebSocket -> (2) Werkzeuge (5) Artikel
  • C&C
    • Cobalt Strike -> (14) Werkzeuge (8) Artikel
    • Werkzeuge
      • (64) Neu hinzugefügt
    • Artikel
      • (258) Neu hinzugefügt
  • Fernsteuerung
    • Werkzeuge
      • (9) Android
      • (5) Linux
      • (17) Windows
      • (4) Apple
      • (90) Neu hinzugefügt
    • Artikel
  • Open-Source-Tools


    pupy

    Werkzeug

    • [5265 Sterne][1m] [Py] n1nj4sec/pupy In Python geschriebene Fernsteuerungs- und Post-Exploitation-Tool, plattformübergreifend (Windows, Linux, OSX, Android)

    Artikel

    • 2020.01 [TheCyberWire] PupyRAT is back. So is the Konni Group. Twitter storm over claims that MBS hacked Jeff Bezos....
    • 2019.03 [hackingarticles] Command & Control Tool: Pupy
    • 2017.11 [chokepoint] Pupy as a Metasploit Payload
    • 2017.10 [boredhackerblog] Pupy shell over Tor
    • 2017.02 [n0where] Open Source Cross Platform RAT: Pupy
    • 2015.10 [hackingarticles] Hack Remote PC using Pupy – Remote Administration Tool

    Covenant

    Werkzeuge

    • [1147 Sterne][6d] [C#] cobbr/covenant Covenant ist ein kollaboratives .NET C2-Framework für Red Teams.
    • [95 Sterne][9d] [C#] cobbr/elite Elite ist die clientseitige Komponente des Covenant-Projekts. Covenant ist ein .NET-Befehls- und Steuerungs-Framework, das darauf abzielt, die Angriffsfläche von .NET zu beleuchten, die Verwendung von offensiven .NET-Tradecrafts zu erleichtern und als kollaborative Befehls- und Steuerungsplattform für Red Teams zu dienen.
    • [31 Sterne][4m] [C#] cobbr/c2bridge C2Bridges ermöglichen Entwicklern, neue benutzerdefinierte Kommunikationsprotokolle zu erstellen und diese schnell in Covenant zu nutzen.

    Artikel

    • 2020.01 [csis] Embedding external DLLs into Covenant Tasks
    • 2020.01 [hakin9] Covenant the .NET based C2 on Kali Linux | by Dan Dieterle
    • 2019.12 [cyberarms] Covenant the .NET based C2 on Kali Linux
    • 2019.12 [rastamouse] Covenant Tasks 101
    • 2019.12 [rsa] Using RSA NetWitness to Detect C&C: Covenant
    • 2019.11 [4hou] Analyse der Nutzung von Covenant
    • 2019.11 [3gstudent] Analyse der Nutzung von Covenant
    • 2019.10 [cobbr] Covenant: Developing Custom C2 Communication Protocols
    • 2019.10 [specterops] Covenant: Developing Custom C2 Communication Protocols
    • 2019.09 [freebuf] Covenant: Ein .NET-Befehls- und Steuerungsframework für Red Teams
    • 2019.09 [stealthbits] Setup, Configuration, and Task Execution with Covenant: The Complete Guide
    • 2019.08 [stealthbits] Next-Gen Open Source C2 Frameworks in a Post PSEmpire World: Covenant
    • 2019.08 [rastamouse] Covenant, Donut, TikiTorch
    • 2019.08 [cobbr] Covenant: The Usability Update
    • 2019.08 [specterops] Covenant: The Usability Update
    • 2019.02 [cobbr] Entering a Covenant: .NET Command and Control
    • 2019.02 [rvr3shll] Entering a Covenant: .NET Command and Control
    • 2019.01 [specterops] Entering a Covenant: .NET Command and Control

    Slackor

    Werkzeug

    • [332 Sterne][12d] [Py] coalfire-research/slackor Ein Golang-Implantat, das Slack als Befehls- und Steuerungsserver nutzt

    Artikel

    • 2019.09 [freebuf] Slackor: Ein in Go geschriebener C&C-Server
    • 2019.08 [freebuf] Slackor: So verwenden Sie Slack als Ihren Befehls- und Steuerungsserver
    • 2019.06 [n00py] Introducing Slackor, a Remote Access Tool Using Slack as a C2 Channel

    QuasarRAT

    Werkzeug

    • [2932 Sterne][10m] [C#] quasar/quasarrat Remote Administration Tool für Windows

    Artikel

    • 2019.10 [UltraHacks] QuasarRAT [Free Download] | [TUTORIAL VIDEO] | Ultra Hacks
    • 2018.09 [malwarebytes] Buggy implementation of CVE-2018-8373 vulnerability used to deliver Quasar RAT
    • 2018.03 [4hou] Tiefgehende Analyse eines bösartigen RTF-Dokuments, das Makrocode zur Verbreitung von NetwiredRC und Quasar RAT nutzt
    • 2018.01 [paloaltonetworks] VERMIN: Quasar RAT and Custom Malware Used I
    • 2017.12 [HackerSploit] QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
    • 2017.11 [n0where] Free, Open-Source Remote Administration Tool for Windows: QuasarRAT
    • 2017.10 [TechnoHacker] Quasar RAT review
    • 2017.10 [rsa] MalSpam Delivers RAT SpyWare Quasar 9-27-2017
    • 2017.01 [paloaltonetworks] Downeks and Quasar RAT Used in Recent Targeted Attacks Against Go

    EvilOSX

    Werkzeug

    • [1376 Sterne][2y] [Py] marten4n6/evilosx Ein böses RAT (Remote Administration Tool) für macOS / OS X.

    Artikel

    • 2019.07 [hackingarticles] EvilOSX-RAT for MacOS/OSX
    • 2019.06 [NullByte] Take Control Over MacOS Computers with EvilOSX [Tutorial]
    • 2018.08 [freebuf] EvilOSX: Ein leistungsstarkes macOS-Remote-Management-Tool (RAT)
    • 2018.07 [pentesttoolz] EvilOSX – Evil Remote Administration Tool (RAT) for macOS/OS X – Kali Linux 2018.2
    • 2018.06 [n0where] Pure python post-exploitation RAT for macOS & OSX: EvilOSX
    • 2018.03 [applehelpwriter] defending against EvilOSX, a python RAT with a twist in its tail
    • 2018.03 [binarydefense] EvilOSX - Binary Defense
    • 2018.03 [binarydefense] EvilOSX
    • 2017.11 [NullByte] EvilOSX RAT - How to build a payload and start a server

    Merlin

    Werkzeug

    • [2568 Sterne][6m] [Go] ne0nd0g/merlin Merlin ist ein plattformübergreifender Post-Exploitation-HTTP/2-Befehls- und Steuerungsserver und Agent, geschrieben in Golang.

    Artikel

    • 2019.03 [hackingarticles] Command and Control Guide to Merlin
    • 2018.02 [lockboxx] Merlin for Red Teams
    • 2017.12 [n0where] Cross-Platform Post-Exploitation HTTP/2 Command & Control Server: Merlin

    Kommerzielle Software


    Team Viewer

    Werkzeuge

    • [405 Sterne][2y] [C++] vah13/extracttvpasswords Tool zum Extrahieren von Passwörtern aus dem TeamViewer-Speicher mit Frida
    • [277 Sterne][2y] [C++] gellin/teamviewer_permissions_hook_v1 Ein Proof-of-Concept der injizierbaren C++-DLL, die nacktes Inline-Hooking und direkte Speichermodifikation verwendet, um Ihre TeamViewer-Berechtigungen zu ändern.
    • [175 Sterne][9d] uknowsec/sharpdecryptpwd Analysiert Programme, deren Passwörter auf Windows-Systemen gespeichert sind, darunter: Navicat, TeamViewer, FileZilla, WinSCP, Xmangager-Produkte (Xshell, Xftp).
    • [59 Sterne][2y] [Py] attackercan/teamviewer-dumper Dump von TeamViewer-ID und Passwort aus dem Arbeitsspeicher
    • [42 Sterne][6d] [C#] v1v1/decryptteamviewer Aufzählung und Entschlüsselung von TeamViewer-Anmeldeinformationen aus der Windows-Registrierung
    • [36 Sterne][5y] [C++] kkar/teamviewer-dumper-in-cpp Dump von TeamViewer-ID, Passwort und Kontoeinstellungen aus einer laufenden TeamViewer-Instanz durch Aufzählung von untergeordneten Fenstern.
    • [25 Sterne][5m] [C++] dydtjr1128/remoteassistance-cpp [WIP] RemoteAssistance ähnlich wie TeamViewer (C++)

    Artikel- 2020.02 [yoroi] Importante Vulnerabilità su TeamViewer

    • 2020.01 [freebuf] „Echte“ Überwachungssoftware von Cyberkriminellen genutzt – wird mangelhafte Ausgabe zu einem weiteren TeamViewer?
    • 2019.11 [sessionstack] TeamViewer, and Alternative Remote Access and Web Conferencing Solutions, Through the Lens of Customer Service
    • 2019.10 [threatbook] „TeamViewer-Hack“ Tatsache oder Übertreibung? Keine Panik! Ein Artikel, der die Gegenmaßnahmen erklärt.
    • 2019.10 [freebuf] TeamViewer angeblich „gehackt“ – Analyse und Schlussfolgerungen
    • 2019.04 [4hou] Angriffe auf Regierungsbehörden mehrerer Länder mittels getarnter TeamViewer-Versionen
    • 2019.04 [0x00sec] Port 5900 open on a MAC that used Teamviewer, trying to access it
    • 2018.09 [blackmoreops] Install TeamViewer on Kali Linux 2018
    • 2018.08 [freebuf] Die von Ihnen heruntergeladene gecrackte TeamViewer 13 könnte schädlich sein
    • 2018.08 [4hou] Angriffe auf Industrieunternehmen mit RMS und TeamViewer
    • 2018.08 [kaspersky] Attacks on industrial enterprises using RMS and TeamViewer
    • 2018.08 [securelist] Attacks on industrial enterprises using RMS and TeamViewer
    • 2017.12 [4hou] Test der Berechtigungslücke in TeamViewer 13.0.5058
    • 2017.12 [3gstudent] Test der Berechtigungslücke in TeamViewer 13.0.5058
    • 2017.12 [3gstudent] Test der Berechtigungslücke in TeamViewer 13.0.5058
    • 2017.12 [malwarebytes] Use TeamViewer? Fix this dangerous permissions bug with an update
    • 2017.11 [360] Analyse eines TeamViewer-basierten Remote-Access-Trojaners, der auf kleine Unternehmen abzielt
    • 2017.08 [freebuf] Extrahieren von Passwörtern aus dem TeamViewer-Speicher mit Frida
    • 2017.04 [4hou] Ein tiefer Einblick, wie Schadsoftware TeamViewer missbraucht
    • 2017.02 [4hou] TeamSpy ist zurück – TeamViewer wird zum Angriffsvektor
    • 2016.12 [trendmicro] New SmsSecurity Variant Roots Phones, Abuses Accessibility Features and TeamViewer
    • 2016.10 [broadanalysis] Rig Exploit Kit via EITEST delivers malicious payload and TeamViewer Remote Control
    • 2016.06 [trendmicro] Unsupported TeamViewer Versions Exploited For Backdoors, Keylogging
    • 2016.06 [] Am weitesten verbreitete Fernsteuerung – TeamViewer gehackt
    • 2016.06 [radware] Has TeamViewer Been Hacked?
    • 2016.06 [fortinet] Threat Landscape Perspectives: TeamViewer Attack – Spy vs. Spy Misdirection?
    • 2016.03 [privacy] Surprise, Hackers Use TeamViewer to Spread Ransomware
    • 2015.08 [volatility] Recovering TeamViewer (and other) Credentials from RAM with EditBox
    • 2015.06 [] Abrufen von Benutzername und Passwort eines laufenden TeamViewer
    • 2014.05 [trendmicro] Remote Help for Family and Friends – Part 1: Installing and Using TeamViewer
    • 2014.02 [webroot] Managed TeamViewer based anti-forensics capable virtual machines offered as a service
    • 2014.01 [robert] Howto install Teamviewer 9.x on Ubuntu >= 12.04 64bit (in my case 13.10)
    • 2013.05 [security] Installing Teamviewer 8 on Kali 64bit (Debian)
    • 2013.03 [securelist] The TeamSpy Crew Attacks – Abusing TeamViewer for Cyberespionage

    Schadsoftware (Teil)


    Gh0st

    Tools

    • [301星][7d] [C++] yuanyuanxiang/simpleremoter Gh0st-basierte Fernsteuerung: realisiert Terminalverwaltung, Prozessverwaltung, Fensterverwaltung, Remote-Desktop, Dateiverwaltung, Sprachverwaltung, Videoverwaltung, Diensteverwaltung, Registrierungsverwaltung usw.
    • [273星][7y] [C++] sin5678/gh0st a open source remote administrator tool
    • [91星][6y] [C++] igh0st/gh0st3.6_src
    • [90星][1m] [C++] zibility/remote In Anlehnung an den Gh0st-Quellcode realisierte PC-Fernhilfe-Software mit Remote-Shell, Dateiverwaltung, Desktopverwaltung, Nachrichtenversand usw.
    • [21星][5m] [C++] holmesian/gh0st-light Altes, vereinfachtes Zeug

    Artikel

    • 2020.01 [z3roTrust] Becoming Untraceable - 12.0_Gh0st_Us3r.dll
    • 2020.01 [rsa] Detecting Gh0st RAT in the RSA NetWitness Platform
    • 2019.06 [binarydefense] Gh0stCringe (Formerly CirenegRAT) - Binary Defense
    • 2019.03 [alienvault] The odd case of a Gh0stRAT variant
    • 2018.11 [trendmicro] Klassifizierung bösartiger Netzwerkdatenströme von Gh0st-RAT-Varianten mittels maschinellem Lernen
    • 2018.08 [traffic] [2018-08-12] KaiXinEK->Gh0stRAT
    • 2018.07 [traffic] [2018-07-16] KaiXinEK->Gh0stRAT
    • 2018.07 [inquest] Field Notes: Malicious HFS Instances Serving Gh0stRAT
    • 2018.07 [360] Initialanalyse einer Gh0st-RAT-Probe
    • 2018.05 [id] CryptGh0st
    • 2018.05 [freebuf] Dekodierung von Netzwerkdaten in Gh0st-RAT-Varianten
    • 2018.04 [freebuf] Analyse des Kommunikationsprotokolls der Gh0st/DaHuiLang-RAT-Familie
    • 2018.04 [360] Analyse des Kommunikationsprotokolls der Gh0st/DaHuiLang-RAT-Familie
    • 2017.12 [traffic] [2017-12-06] KaiXinEK->Gh0stRAT
    • 2016.06 [cysinfo] Hunting and Decrypting Communications of Gh0st RAT in Memory
    • 2014.05 [pediy] [Original] Analyse des Verbindungsfehlers von Gh0st3.6 unter Windows 7
    • 2014.04 [pediy] [Diskussion] IOCP-Sendebug in Gh0st3.6
    • 2014.03 [trendmicro] Kunming Attack Leads to Gh0st RAT Variant
    • 2013.08 [pediy] Sekundäre Gh0st
    • 2013.06 [trendmicro] Targeted Attack in Taiwan Uses Infamous Gh0st RAT
    • 2012.11 [trendmicro] DaRK DDoSseR Leads to Gh0st RAT
    • 2012.06 [alienvault] New MaControl variant targeting Uyghur users, the Windows version using Gh0st RAT
    • 2012.05 [forcepoint] The Amnesty International UK website was compromised to serve Gh0st RAT [Update]

    NanoCore

    Tools

    • [2星][10m] [Py] jacobpimental/nanocore_extractor Extracts nanocore sample from compile AutoIT script

    Artikel

    • 2020.01 [molly] NanoCore: The RAT that keeps on keeping on. How to detect and prove an infection.
    • 2019.11 [4hou] Doppelladende ZIP-Datei verbreitet Nanocore RAT
    • 2019.10 [morphisec] NanoCore RAT Under the Microscope
    • 2019.06 [myonlinesecurity] More AgentTesla keylogger and Nanocore RAT in one bundle
    • 2019.06 [myonlinesecurity] Nanocore RAT via fake DHL failed delivery in Chinese
    • 2019.06 [4hou] Analyse der Angriffskette der NanoCore-Crimeware
    • 2019.06 [yoroi] Dissecting NanoCore Crimeware Attack Chain
    • 2019.05 [myonlinesecurity] nanocore RAT via fake order in password protected word doc with wrong password
    • 2019.05 [myonlinesecurity] Fake Fedex Express Shipment For Pickup in iso delivers nanocore using Sendgrid
    • 2019.05 [goggleheadedhacker] Unpacking NanoCore Sample Using AutoIT
    • 2019.03 [carbonblack] TAU Threat Intelligence Notification: NanoCore – Old Malware, New Tricks!
    • 2019.01 [myonlinesecurity] Fake Autec Power purchase Order delivers Nanocore RAT
    • 2019.01 [myonlinesecurity] Nanocore via fake order using dde in csv files
    • 2019.01 [myonlinesecurity] Nanocore RAT via fake order emails
    • 2019.01 [malware] 2019-01-04 - MALSPAM PUSHES NANOCORE RAT
    • 2018.11 [myonlinesecurity] Fake Payment Receipt delivers Nanocore RAT malware
    • 2018.06 [UltraHacks] NanoCore [Free Download] [No Virus] [DL] | Ultra Hacks
    • 2018.04 [myonlinesecurity] Fake PAYMENT CONFIRMATION emails deliver Nanocore RAT
    • 2018.04 [myonlinesecurity] Nanocore Rat delivered via fake order emails
    • 2018.04 [myonlinesecurity] Nanocore via fake Purchase order malspam using Microsoft Office Equation Editor exploits
    • 2018.04 [myonlinesecurity] Nanocore RAT delivered by fake order malspam
    • 2018.02 [krebsonsecurity] Bot Roundup: Avalanche, Kronos, NanoCore
    • 2017.11 [myonlinesecurity] Fake Product Enquiry malspam delivers Nanocore RAT
    • 2017.10 [fortinet] PDF Phishing Leads to Nanocore RAT, Targets French Nationals
    • 2017.10 [fortinet] Bösartige PDF-Datei mit eingebettetem JavaScript-Skript, lädt beim Start über einen Google Drive-Freigabelink eine HTA-Datei herunter, die dann NanoCore herunterlädt und ausführt.
    • 2017.08 [myonlinesecurity] Angelika Rodriguez – [email protected] – Purchase Order malspam delivers nanocore RAT
    • 2017.05 [netskope] NanocoreRAT delivery via cloud storage apps shifts from .uue to .r11
    • 2017.03 [itsjack] Nanocore Cracked Alcatraz – Leaving The Door Open
    • 2016.10 [sans] Malspam delivers NanoCore RAT
    • 2016.02 [paloaltonetworks] NanoCoreRAT Behind an Increase in Tax-Themed Phishin
    • 2015.11 [f] Halloween RAT: NanoCore Served Via PageFair Service
    • 2015.04 [ensilo] NanoCore RAT: It’s Not 100% Original

    NjRat

    Tools

    • [143星][2y] [Visual Basic .NET] alibawazeeer/rat-njrat-0.7d-modded-source-code NJR
    • [128星][8d] [Visual Basic] mwsrc/njrat njRAT SRC Extract
    • [14星][5m] [C#] nyan-x-cat/njrat-0.7d-stub-csharp njRAT C# Stub - Fixed For PowerShell
    • [3星][2y] [Py] seep1959/njutils A client and chat program for njrat 0.6.4, 0.7d, and 0.7d golden edition.

    Artikel

    • 2019.12 [carbonblack] Threat Analysis Unit (TAU) Threat Intelligence Notification: njRAT
    • 2019.09 [freebuf] Die Gorgon-APT-Gruppe schlägt wieder zu: Der mühsame Weg von DropBox zu njRAT
    • 2019.05 [morphisec] A look at Hworm / Houdini AKA njRAT
    • 2019.05 [myonlinesecurity] Fake Payment receipt vbs drops njrat bladabindi downloads Agent Tesla via Sendspace.
    • 2018.11 [trendmicro] AutoIt-kompilierter Wurm, der über Wechselmedien verbreitet und eine dateilose Version von njRAT abwirft
    • 2018.06 [360] Alter Baum, neue Blüten – Analysebericht zur njRAT-Familie
    • 2018.06 [freebuf] Technische Diskussion | NjRAT umgeht 360 Antivirus durch Base64-Codierung und Code-Obfuskation
    • 2018.04 [UltraHacks] njRAT v0.7 | Tutorial | www.ultrahacks.org | Ultra Hacks
    • 2018.03 [broadanalysis] Guest Blog Post: njRat Analysis with Volatility
    • 2018.01 [rsa] Malspam delivers njRAT 1-11-2018
    • 2017.12 [malwarenailed] Revisiting HWorm and NjRAT
    • 2016.12 [freebuf] Die umfassendste Analyse des njRAT-Kommunikationsprotokolls aller Zeiten
    • 2016.08 [MalwareAnalysisForHedgehogs] Malware Analysis - Unpacking njRAT Protected by Confuser v.1.9 and others
    • 2016.01 [sensecy] Is There A New njRAT Out There?
    • 2015.12 [sec] Trojaner-Informationsanalyse: njRAT & H-Worm
    • 2015.11 [alienvault] KilerRat: Taking over where Njrat remote access trojan left off
    • 2015.08 [virusbulletin] Paper: Life after the apocalypse for the Middle Eastern NJRat campaign
    • 2014.08 [mcafee] Trailing the Trojan njRAT
    • 2014.08 [mcafee] Trailing the Trojan njRAT
    • 2014.01 [rsa] Detecting njRAT in Your Environment

    Revenge RAT

    Tools

    • [21星][2m] [C#] nyan-x-cat/revengerat-stub-cssharp Revenge-RAT C# Stub - Fixed

    Artikel

    • 2020.01 [malware] 2020-01-15 - QUICK POST: MALSPAM PUSHING REVENGE RAT
    • 2019.11 [fortinet] Double Trouble: RevengeRAT and WSHRAT
    • 2019.09 [360] Revenge-RAT is used in phishing emails attacks against Italy
    • 2019.04 [4hou] Aggah-Kampagne zur Verbreitung von RevengeRAT mittels Phishing-E-Mails
    • 2019.03 [alienvault] Mapping TrickBot and RevengeRAT with MITRE ATT&CK and AlienVault USM Anywhere
    • 2019.02 [4hou] Neue Version der Revenge RAT-Malware im Umlauf
    • 2018.04 [dissectmalware] Stealthy VBScript dropper dropping Revenge RAT
    • 2017.10 [rsa] Malspam Delivers Revenge RAT October-2017
    • 2016.08 [deniable] Lurking Around Revenge-RAT

    PlugX### Werkzeuge

    • [28Sterne][7y] [Py] kcreyts/plugxdecoder Dekodiert PlugX-Datenverkehr und verschlüsselte/komprimierte Artefakte

    Artikel

    • 2020.01 [hexacorn] The Wizard of X – Oppa PlugX style, Part 2
    • 2019.11 [BorjaMerino] Rebind Socket Windows: PoC PlugX Controller
    • 2018.06 [countuponsecurity] Digital Forensics – PlugX and Artifacts left behind
    • 2018.05 [countuponsecurity] Malware Analysis – PlugX – Part 2
    • 2018.02 [4hou] Aufdeckung der Angriffsfähigkeiten der PlugX-Malware-Familie
    • 2018.02 [360] PlugX Malware-Analysebericht
    • 2018.02 [countuponsecurity] Malware Analysis – PlugX
    • 2017.09 [fortinet] Deep Analysis of New Poison Ivy/PlugX Variant - Part II
    • 2017.09 [fortinet] Detaillierte Analyse der neuen Poison Ivy/PlugX-Variante
    • 2017.09 [360] Stack overflow in PlugX RAT
    • 2017.07 [hexacorn] The Wizard of X – Oppa PlugX style
    • 2017.02 [jpcert] PlugX + Poison Ivy = PlugIvy? - PlugX Integrating Poison Ivy’s Code -
    • 2016.06 [airbuscybersecurity] Getting a PlugX builder
    • 2016.06 [cylance] CylancePROTECT® vs. PlugX – JTB Breach Affects 7.93 Million People in Japan
    • 2016.03 [securelist] PlugX malware: A good hacker is an apologetic hacker
    • 2015.11 [volatility] PlugX: Memory Forensics Lifecycle with Volatility
    • 2015.09 [cyintanalysis] Using threat_note To Track Campaigns: Returning to PIVY and PlugX Infrastructure
    • 2015.09 [airbuscybersecurity] Volatility plugin for PlugX updated
    • 2015.08 [rebsnippets] PlugX Chronicles
    • 2015.08 [cyintanalysis] Threat Analysis: Poison Ivy and Links to an Extended PlugX Campaign
    • 2015.08 [airbuscybersecurity] Latest changes in PlugX
    • 2015.05 [paloaltonetworks] PlugX Uses Legitimate Samsung Application for DLL Sid
    • 2015.04 [freebuf] Malware-Analyse: PlugX-Fernsteuerung in offizielle taiwanesische Versionen von League of Legends und Path of Exile eingeschleust
    • 2015.01 [jpcert] Analysis of a Recent PlugX Variant - "P2P PlugX"
    • 2015.01 [] A Closer Look at PlugX from League of Legends / Path of Exile
    • 2015.01 [trendmicro] PlugX Malware Found in Official Releases of League of Legends, Path of Exile
    • 2014.06 [trendmicro] PlugX RAT With “Time Bomb” Abuses Dropbox for Command-and-Control Settings
    • 2014.06 [lastline] An Analysis of PlugX Using Process Dumps from High-Resolution Malware Analysis
    • 2014.01 [airbuscybersecurity] PlugX "v2": meet "SController"
    • 2014.01 [airbuscybersecurity] PlugX: some uncovered points
    • 2013.12 [lastline] An Analysis of PlugX Malware
    • 2013.05 [freebuf] FireEye: PlugX in neuem Gewand – APT-Angriffsanalyse auf chinesische politische Aktivitäten
    • 2013.04 [trendmicro] New Wave of PlugX Targets Legitimate Apps
    • 2013.04 [securelist] Winnti returns with PlugX
    • 2012.09 [freebuf] Ausländische Experten decken PlugX-Entwickler auf – Vollständige Analyse des gezielten Angriffs
    • 2012.09 [alienvault] The connection between the Plugx Chinese gang and the latest Internet Explorer Zeroday
    • 2012.09 [trendmicro] Unplugging PlugX Capabilities
    • 2012.09 [alienvault] Tracking down the author of the PlugX RAT
    • 2012.09 [freebuf] Neues PlugX-Fernsteuerungswerkzeug wird ausgenutzt und greift japanische Regierung per Phishing an
    • 2012.09 [trendmicro] PlugX: New Tool For a Not So New Campaign

    RemcosRAT

    • 2019.10 [fortinet] New Variant of Remcos RAT Observed In the Wild
    • 2019.09 [myonlinesecurity] Some changes to Remcos Rat persistence method
    • 2019.09 [myonlinesecurity] Fake invoice tries to deliver Remcos RAT
    • 2019.09 [freebuf] Analyse einer Remcos-RAT-Variante in Phishing-E-Mails
    • 2019.08 [trendmicro] Analysis: New Remcos RAT Arrives Via Phishing Email
    • 2019.06 [myonlinesecurity] Remcos Rat via fake invoice using multiple delivery methods.
    • 2019.06 [HackerSploit] Remcos RAT Review - The Most Advanced Remote Access Tool
    • 2018.11 [myonlinesecurity] More Fake DHL invoices delivering Remcos RAT via office XML files
    • 2018.10 [myonlinesecurity] Fake DHL READ : (DHL Express) -Delivery Address Confirmation delivers Remcos Rat
    • 2018.09 [myonlinesecurity] Fake Purchase Order email delivers Remcos RAT
    • 2018.09 [360] Aufdeckung des Botnetzes unter Remcos
    • 2018.08 [securityledger] Cisco Links Remote Access Tool Remcos to Cybercriminal Underground
    • 2018.08 [talosintelligence] Picking Apart Remcos Botnet-In-A-Box
    • 2018.08 [UltraHacks] Remcos RAT Tutorial | Remote Administration Tool | Ultra Hacks
    • 2018.07 [myonlinesecurity] Fake DHL “Alert! Shipment Notification” delivers Remcos RAT
    • 2018.05 [fortinet] Remcos-Fernsteuerungsvariante verbreitet sich durch Ausnutzung von CVE-2017-11882
    • 2018.04 [myonlinesecurity] Remcos RAT delivered by fake ” your workers are fighting” message
    • 2018.04 [myonlinesecurity] Remcos RAT delivered via fake CCICM international debt recovery service
    • 2018.04 [myonlinesecurity] Fake Payment recovery email spoofing CCICM international debt recovery service delivers Remcos rat via Microsoft Equation Editor Exploits
    • 2018.03 [tencent] Neuer Remcos-Fernsteuerungstrojaner führt Echtzeitangriffe durch Ausnutzung von CVE-2017-11882 durch
    • 2018.03 [myonlinesecurity] Fake order spoofed from Finchers ltd Sankyo-Rubber delivers Remcos RAT via ACE attachments
    • 2017.09 [malwarebreakdown] Malvertising Leads to RIG EK and Drops Remcos RAT.
    • 2017.09 [trendmicro] Cloud-Plattform Autodesk® A360 wird zur Verbreitung von Adwind, Remcos, Netwire RAT und anderer Malware genutzt
    • 2017.08 [cybereason] Cybereason creates 'vaccine' to stop Remcos RAT
    • 2017.02 [fortinet] REMCOS: A New RAT In The Wild

    L0rdixRAT

    • 2019.08 [bromium] Decrypting L0rdix RAT’s C2
    • 2019.07 [bromium] An Analysis of L0rdix RAT, Panel and Builder
    • 2018.11 [ensilo] L0RDIX: Multipurpose Attack Tool

    LodaRAT

    • 2020.02 [talosintelligence] Loda RAT Grows Up

    GulfRAT

    • 2020.01 [TheCyberWire] Phishing with a RAT in the Gulf. More on how Jeff Bezos was hacked. Microsoft discloses data...
    • 2020.01 [TheCyberWire] Escalation in the Gulf as a US air strike kills Iran’s Quds commander. Travelex and RavnAir...
    • 2019.08 [nettitude] Tanker Cyber Attacks taking place in the Gulf
    • 2017.09 [mikefrobbins] PowerShell Toolmaking session this Saturday, September 30th at Gulf Coast Code Camp 2017 in Mobile, Alabama
    • 2016.11 [fireeye] FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region
    • 2016.03 [elearnsecurity] Visit eLearnSecurity on Gulf Information Security and Gulf Expo 2016 in Dubai
    • 2015.07 [welivesecurity] New report explains gulf between security experts and non-experts
    • 2010.08 [publicintelligence] Los Zetas and Gulf Cartel Perpetrators of Mexican Drug Trafficking Violence Organizational Chart
    • 2010.05 [publicintelligence] BP Minerals Management Service Workshop Brief: Unlocking Gulf of Mexico “Technological Challenges”

    NetWireRAT

    • 2020.01 [securityintelligence] New NetWire RAT Campaigns Use IMG Attachments to Deliver Malware Targeting Enterprise Users
    • 2019.11 [carbonblack] Active C2 Discovery Using Protocol Emulation Part1 (HYDSEVEN NetWire)
    • 2019.09 [fortinet] New NetWire RAT Variant Being Spread Via Phishing
    • 2019.08 [malware] 2019-08-23 - DATA DUMP (URSNIF, RIG EK, NETWIRE RAT)
    • 2019.04 [myonlinesecurity] Fake DHL Shipment Notification delivers Netwire Trojan
    • 2018.11 [traffic] [2018-11-21] HookAds->FalloutEK->AZORult->NetWireRAT
    • 2017.11 [myonlinesecurity] Fake HSBC Advising Service Payment Advice malspam delivers Netwire trojan
    • 2017.10 [myonlinesecurity] Fake HSBC Swift Copy delivers Netwire trojan
    • 2017.09 [TechnoHacker] NetWire HKCU/Run vs ActiveX Startup
    • 2017.08 [TechnoHacker] Netwire Tutorial: How to Sign the Android Host
    • 2017.04 [TechnoHacker] How to crypt Netwire with Cyberseal
    • 2017.04 [TechnoHacker] Netwire RAT Review
    • 2014.08 [paloaltonetworks] NetWire and MITRE
    • 2014.08 [paloaltonetworks] New Release: Decrypting NetWire C

    JhoneRAT

    • 2020.01 [talosintelligence] JhoneRAT: Cloud based python RAT targeting Middle Eastern countries

    Dacls

    • 2019.12 [360] Lazarus Group verwendet Dacls RAT zum Angriff auf Linux-Plattformen
    • 2019.12 [360] Dacls, the Dual platform RAT

    BlackRemote

    • 2019.12 [carbonblack] Threat Analysis Unit (TAU) Threat Intelligence Notification: BlackRemote RAT

    Orcus

    • 2019.11 [krebsonsecurity] Orcus RAT Author Charged in Malware Scheme
    • 2019.01 [morphisec] New Campaign Delivers Orcus RAT
    • 2018.04 [freebuf] Beispielanalyse eines Orcus-Fernsteuerungstrojaners, der über SYLK-Dateien verbreitet wird
    • 2017.12 [fortinet] Circle of the fraud: more information about Bitcoin Orcus RAT campaign
    • 2017.12 [fortinet] Circle of the fraud: more information about Bitcoin Orcus RAT campaign
    • 2017.12 [fortinet] A Peculiar Case of Orcus RAT Targeting Bitcoin Investors
    • 2017.12 [fortinet] Orcus-Fernsteuerung zielt auf Bitcoin-Investoren ab, getarnt als Bitcoin-Handelsbot Gunbot zur Verbreitung
    • 2017.05 [freebuf] Schritte zur Lösung der Orcus VM
    • 2017.04 [hackingarticles] Hack the Orcus VM CTF Challenge
    • 2017.04 [techanarchy] VulnHub Orcus Solution
    • 2017.03 [vulnhub] hackfest2016: Orcus
    • 2017.03 [vulnhub] hackfest2016: Orcus
    • 2016.08 [deniable] Cracking Orcus RAT
    • 2016.08 [deniable] Cracking Orcus RAT
    • 2016.08 [deniable] Cracking Orcus RAT
    • 2016.08 [paloaltonetworks] Orcus – Birth of an unusual plugin bu
    • 2016.07 [krebsonsecurity] Canadian Man Behind Popular ‘Orcus RAT’

    NukeSped

    • 2019.10 [fortinet] A Deep-Dive Analysis of the NukeSped RATs

    DarkComet- 2018.09 [UltraHacks] How to setup DarkCometRAT 5.3.1 + Portforward

    • 2018.04 [freebuf] CVE-2017-11882 neue Entwicklungen: Nutzung von AutoIT-Skripten zur Freisetzung von DarkComet-Hintertür
    • 2018.03 [tencent] CVE-2017-11882 neue Entwicklungen: Nutzung von AutoIT-Skripten zur Freisetzung von DarkComet-Hintertür
    • 2017.10 [rsa] Malspam Delivers DarkComet RAT October-2017
    • 2017.01 [HackingMonks] Darkcomet Rat Tutorial (Trojans are awesome)
    • 2016.02 [hackingarticles] Hack Remote PC using Darkcomet RAT with Metasploit
    • 2015.11 [TechnoHacker] How to setup DarkComet RAT [Voice Tutorial] [Download Link]
    • 2015.07 [SecurityBSidesLondon] Kevin Breen - DarkComet From Defense To Offense - Identify your Attacker
    • 2015.03 [heimdalsecurity] Security Alert: Infamous DarkComet RAT Used In Spear Phishing Campaigns
    • 2015.03 [sketchymoose] Smooshing the Square Peg into the Round Hole: DarkComet Plugin for 64-bit images
    • 2012.07 [freebuf] DarkComet RAT-Autor gibt Einstellung des Projekts bekannt
    • 2012.06 [freebuf] [Update] Ein leistungsstarkes Fernsteuerungstool – DarkComet RAT V5.3.1
    • 2012.06 [malwarebytes] You dirty RAT! Part 1: DarkComet
    • 2012.04 [trendmicro] Fake Skype Encryption Software Cloaks DarkComet Trojan
    • 2012.04 [toolswatch] DarkComet-RAT Remote Administration Tool v5.1.1 released
    • 2012.03 [quequero] DarkComet Analysis – Understanding the Trojan used in Syrian Uprising
    • 2012.02 [trendmicro] DarkComet Surfaced in the Targeted Attacks in Syrian Conflict
    • 2011.08 [toolswatch] DarkComet-RAT (Remote Administration Tool) v4.0 Fix 1 available
    • 2011.05 [toolswatch] DarkComet-RAT v3.3 available
    • 2011.01 [toolswatch] (EXCLUSIVE) DarkComet-RAT updated to v3.0.1
    • 2011.01 [toolswatch] EXCLUSIVE : DarkComet-RAT 3.0 released (Impressive RAT tool)

    WarZone RAT

    • 2018.11 [UltraHacks] Warzone RAT C++ | Hidden VNC [PROMOTION VIDEO]| Ultra Hacks

    BlackShades

    • 2017.01 [TechnoHacker] Blackshades Revisited
    • 2016.02 [TechnoHacker] How to use Blackshades [download link]
    • 2016.02 [TechnoHacker] How to setup Blackshades RAT [Voice Tutorial] [download link]
    • 2014.05 [malwarebytes] Taking off the Blackshades
    • 2014.05 [endgame] Blackshades: Why We Should Care About Old Malware
    • 2014.05 [trendmicro] The Blackshades RAT – Entry-Level Cybercrime
    • 2014.05 [publicintelligence] FBI Blackshades Remote Access Tool Private Sector Bulletins and Domain List
    • 2014.05 [alienvault] Blackshades Smackdown & Poking China in the Eye
    • 2014.05 [cylance] A Study in Bots: BlackShades Net
    • 2014.05 [welivesecurity] Behind Blackshades: a closer look at the latest FBI cyber crime arrests
    • 2014.05 [krebsonsecurity] ‘Blackshades’ Trojan Users Had It Coming
    • 2014.05 [malwaretech] FBI Cybercrime Crackdown – Blackshades
    • 2012.07 [malwarebytes] BlackShades Co-Creator Arrested!
    • 2012.06 [malwarebytes] BlackShades in Syria
    • 2012.06 [citizenlab] Syrian Activists Targeted with BlackShades Spy Software
    • 2012.06 [malwarebytes] You Dirty RAT! Part 2 – BlackShades NET

    DenesRAT

    • 2019.10 [nsfocus] OceanLotus (APT32) Organisation: DenesRAT-Trojaner und Analyse der zugehörigen Angriffskette

    WSH RAT

    • 2019.10 [angelalonso] WSH RAT - Analysis of the code
    • 2019.10 [angelalonso] Fudcrypt using H-Worm from WSH RAT
    • 2019.09 [freebuf] Hacker kaufen neuartige WSH RAT-Variantenproben, um Bankkunden anzugreifen
    • 2019.09 [angelalonso] WSH RAT and the link to unknowcrypter and Fudcrypt

    Qrypter RAT

    • 2018.04 [4hou] Analyse der Betriebsbedingungen des zunehmend populären Qrypter RAT
    • 2017.12 [angelalonso] Qrypter Java RAT using Tor

    Adwind

    • 2019.08 [4hou] Adwind-Fernsteuerung wird derzeit häufig in Angriffen auf öffentliche Versorgungsunternehmen eingesetzt
    • 2018.10 [reversinglabs] eWeek: Cisco Talos and ReversingLabs warn that the Adwind Remote Access Trojan (RAT) has added capabilities that enable it bypass some anti-virus technologies
    • 2018.04 [4hou] Spam-Kampagne nutzt Hintertüren von XTRAT, DUNIHI und Adwind
    • 2018.04 [trendmicro] Trend-Micro-Forscher beobachten Spam, der plattformübergreifende Adwind-Fernsteuerung verbreitet, zusammen mit den Hintertüren XTRAT, DUNIHI und Loki
    • 2018.04 [ensilo] enSilo Blocks New Variant of Adwind RAT
    • 2018.03 [OALabs] Analyzing Adwind / JRAT Java Malware
    • 2018.03 [heimdalsecurity] Security Alert: Spam Campaign Spreads Adwind RAT variant, Targeting Computer Systems
    • 2018.02 [fortinet] New jRAT/Adwind Variant Being Spread With Package Delivery Scam
    • 2018.02 [rsa] Winds of Winter - MalSpam Delivers Adwind RAT 2-1-2018
    • 2018.02 [myonlinesecurity] Fake Swift Copy malspam via compromised sites delivering Java Adwind/ QRAT /JRAT Trojan
    • 2017.12 [myonlinesecurity] Fake “Your UPS Invoice Is Ready” malspam delivers Java Adwind / Java JRAT Trojan
    • 2017.08 [netskope] Adwind RAT employs new obfuscation techniques
    • 2017.07 [trendmicro] Spam Campaign Delivers Cross-platform Remote Access Trojan Adwind
    • 2017.03 [freebuf] Adwind RAT zielt auf Unternehmen ab, betrifft über 100 Länder und Regionen
    • 2017.01 [codemetrix] Decrypting Adwind jRAT jBifrost trojan
    • 2016.08 [fortinet] JBifrost: Yet Another Incarnation of the Adwind RAT
    • 2016.07 [heimdalsecurity] Security Alert: Adwind RAT Used in Targeted Attacks with Zero AV Detection
    • 2016.02 [securelist] Expert: cross-platform Adwind RAT
    • 2016.02 [kaspersky] The wind that smells like RAT: The story of Adwind MaaS
    • 2013.11 [crowdstrike] Adwind RAT Rebranding

    CannibalRAT

    • 2018.02 [talosintelligence] CannibalRAT targets Brazil

    jRAT

    • 2018.10 [cofense] H-Worm and jRAT Malware: Two RATs are Better than One
    • 2018.08 [Sebdraven] Lammers, stealers and RATs: same technics like Formbook malware to install JRAT and HawkEye…
    • 2018.03 [trustwave] Crypter-as-a-Service Helps jRAT Fly Under The Radar

    jsRAT

    • 2018.02 [netskope] ShortJSRAT leverages cloud with scriptlets
    • 2017.07 [rsa] Recreating the Crime Scene - A JSRat Story
    • 2016.05 [evi1cg] JSRAT verschiedene Startmethoden
    • 2016.03 [hackingarticles] Hack Remote Windows 10 PC using JSRAT
    • 2015.07 [secist] Verwaltung von Windows 10-Systemen mit JSRAT aus der Ferne

    CrossRat

    • 2018.01 [360] Analyse einer plattformübergreifenden Malware in globalen Cyber-Spionageaktivitäten – CrossRAT (Teil 2)
    • 2018.01 [4hou] Analyse der CrossRat-Fernsteuerungssoftware
    • 2018.01 [360] Analyse einer plattformübergreifenden Malware in globalen Cyber-Spionageaktivitäten – CrossRAT (Teil 1)
    • 2018.01 [objective] Analyse der plattformübergreifenden Fernsteuerung CrossRAT, die in globalen Cyber-Spionageaktivitäten eingesetzt wird

    ArmaRat

    • 2018.09 [360] ArmaRat: Zwei Jahre andauernde Spionageaktivitäten gegen iranische Nutzer

    RokRAT

    • 2018.01 [morphisec] Threat Profile: RokRAT
    • 2017.12 [MalwareAnalysisForHedgehogs] Malware Analysis - ROKRAT Unpacking from Injected Shellcode
    • 2017.11 [talosintelligence] ROKRAT Reloaded
    • 2017.06 [alienvault] A RAT that Tweets: New ROKRAT Malware Hides behind Twitter, Amazon, and Hulu Traffic
    • 2017.04 [360] Analyse des ROKRAT-Trojaners unter Nutzung von Cloud-Plattformen
    • 2017.04 [talosintelligence] ROKRAT-Fernsteuerungsanalyse: Von Phishing zu Payload, Nutzung von Twitter/Yandex/Mediafire als C&C.

    CatKARAT

    • 2018.01 [hackingarticles] TCP & UDP Packet Crafting with CatKARAT

    TheFatRat

    • 2018.11 [freebuf] Technischer Beitrag | Sehen Sie, wie ich mit TheFatRat Ihr Android-Handy hacke
    • 2017.11 [TheHackerStuff] TheFatRat - Hacking Over WAN - Embedding Payload in Original Android APK - Without Port Forwarding
    • 2016.12 [TheHackerStuff] Kali Linux - TheFatRat - Creating an Undetectable Backdoor - Bypass all AntiVirus
    • 2016.09 [freebuf] TheFatRat: Vereinfachtes Backdoor-Generierungstool für Msfvenom
    • 2016.07 [hackingarticles] Hack Remote Windows 10 PC using TheFatRat

    OmniRAT

    • 2017.07 [skycure] Nasty backdoor OmniRAT is back, disguised as GhostCtrl on Android mobile devices
    • 2015.11 [freebuf] Variante des OmniRAT-Trojaners wird bösartig genutzt

    LuminosityLink

    • 2018.10 [welivesecurity] LuminosityLink RAT pack leader jailed 30 months in the US
    • 2018.02 [paloaltonetworks] RAT Trapped? LuminosityLink Falls Foul of Vermin Eradicatio
    • 2017.05 [UltraHacks] How to setup LuminosityLink RAT with nVPN | PORTFORWARD FIX!!!
    • 2017.05 [umbrella] The Weather Report: Seamless Campaign, LuminosityLink RAT, and OG-Miner!
    • 2017.03 [myonlinesecurity] Request for 1st new order proforma invoice malspam delivers LuminosityLink RAT
    • 2016.07 [paloaltonetworks] Investigating the LuminosityLink Remote Access Trojan Conf

    Sonstige- 2020.02 [proofpoint] Proofpoint Q4 2019 Threat Report and Year in Review — The Year of the RAT Ends with More of the Same

    • 2020.01 [sentinelone] CISO Essentials | How Remote Access Trojans Affect the Enterprise
    • 2020.01 [TheCyberWire] RATs, backdoors, and a remote code execution zero-day. Hoods breach Mitsubishi Electric. Telnet...
    • 2020.01 [freebuf] Analysebericht über das Einschleusen von Remote-Access-Trojanern in gültige digitale Zertifikate
    • 2020.01 [rambus] Cable Haunt vulnerability can give hackers remote access to approximately 200 million cable modems
    • 2020.01 [proofpoint] Threat Insight 2019 in Review: Year of the RAT
    • 2019.12 [ptsecurity] Turkish tricks with worms, RATs… and a freelancer
    • 2019.12 [infosecinstitute] Malware spotlight: What is a Remote Access Trojan (RAT)?
    • 2019.12 [UltraHacks] Dark Shades Android RAT | Ultra Hacks
    • 2019.11 [broadanalysis] Fallout Exploit Kit delivers suspect Remote Access Trojan (RAT)
    • 2019.11 [carbonblack] Threat Analysis Unit (TAU) Threat Intelligence Notification: AsyncRAT
    • 2019.11 [proofpoint] Proofpoint Q3 2019 Threat Report — Emotet’s return, RATs reign supreme, and more
    • 2019.10 [tencent] KuaiGoMiner steuert Zehntausende Computer zum Mining, setzt Remote-Access-Trojaner frei und stiehlt Geheimnisse
    • 2019.10 [4hou] KuaiGoMiner steuert Zehntausende Computer zum Mining, setzt Remote-Access-Trojaner frei und stiehlt Geheimnisse
    • 2019.10 [proofpoint] TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader
    • 2019.10 [tencent] „Moonlight“-Wurm bedroht Hochschulnetze – infizierte Computer werden ferngesteuert
    • 2019.10 [4hou] „Moonlight“-Wurm bedroht Hochschulnetze – infizierte Computer werden ferngesteuert
    • 2019.10 [freebuf] Spionage-Spaziergang: Analyse des ersten Android-RAT-Tools
    • 2019.09 [4hou] Schädlinge nutzen phpStudy RCE-Lücke aus, um massenhaft Rechner kapern und vier Remote-Access-Trojaner einschleusen
    • 2019.09 [aliyun] Einsatz von BadUSB zur Trojaner-Fernsteuerung
    • 2019.09 [sensecy] ARABIC-SPEAKING THREAT ACTOR RECYCLES THE SOURCE CODE OF POPULAR RAT SPYNOTE AND SELLS IT IN THE DARK WEB, AS NEW
    • 2019.08 [securelist] Fully equipped Spying Android RAT from Brazil: BRATA
    • 2019.08 [talosintelligence] RAT Ratatouille: Backdooring PCs with leaked RATs
    • 2019.08 [malware] 2019-08-26 - DATA DUMP: SOCGHOLISH CAMPAIGN PUSHES NETSUPPORT RAT
    • 2019.08 [fortinet] Fake Indian Income Tax Calculator Delivers xRAT Variant
    • 2019.07 [tencent] Neue Aktivitäten der Familie „Handelsbriefe“: Verbreitung des Remote-Access-Trojaners RevetRAT per Phishing-Mails
    • 2019.07 [freebuf] Wissenswertes über Remote-Access-Trojaner
    • 2019.07 [trendmicro] Spam Campaign Targets Colombian Entities with Custom-made ‘Proyecto RAT,’ Uses Email Service YOPmail for C&C
    • 2019.07 [freebuf] Kernkomponente von APT34: Glimpse – Nachbildung und Traffic-Analyse der Fernsteuerung
    • 2019.07 [d] Red Team Diary, Entry #1: Making NSA’s PeddleCheap RAT Invisible
    • 2019.07 [yoroi] Spotting RATs: Tales from a Criminal Attack
    • 2019.07 [cybersecpolitics] Book Review: Delusions of Intelligence, R.A. RATCLIFF
    • 2019.07 [4hou] Auf der Spur der Trojaner-Entwicklung: Horizontale Analyse der mehrfachen Versionen des APT32-RATs Ratsnif
    • 2019.07 [4hou] Ein kleiner Überblick über Remote-Access-Trojaner
    • 2019.07 [freebuf] Versand bösartiger LNK-Dateien mit JwsclTerminalServer zur Fernsteuerung und Informationsbeschaffung
    • 2019.07 [securityintelligence] Taking Over the Overlay: What Triggers the AVLay Remote Access Trojan (RAT)?
    • 2019.07 [securityintelligence] Taking Over the Overlay: Reverse Engineering a Brazilian Remote Access Trojan (RAT)
    • 2019.07 [talosintelligence] RATs and stealers rush through “Heaven’s Gate” with new loader
    • 2019.06 [4hou] Vorsicht vor dem H-Worm-Wurm, der sich als Filmtrailer tarnt: Ein unbedachter Klick auf den Anhang führt zum Remote-Access-Trojaner
    • 2019.06 [nightst0rm] Tôi đã chiếm quyền điều khiển của rất nhiều trang web như thế nào?
    • 2019.06 [4hou] TA505 setzt in neuesten Angriffskampagnen HTML, RATs und andere Techniken ein
    • 2019.06 [trendmicro] Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns
    • 2019.05 [4hou] Babylon RAT verbessert die Multitasking-Fähigkeit von Malware
    • 2019.05 [360] Notiz zu einer Spam-Kampagne mit XLM-Makro zum Einschleusen eines Fernzugriffs-Tools
    • 2019.05 [arxiv] [1905.07273] Finding Rats in Cats: Detecting Stealthy Attacks using Group Anomaly Detection
    • 2019.05 [freebuf] Praxis mit dem Python-basierten BS-RAT Ares
    • 2019.05 [4hou] C&C-Fernsteuerungstool: WebSocket C2
    • 2019.04 [paloaltonetworks] BabyShark Malware Part Two – Attacks Continue Using KimJongRAT
    • 2019.04 [freebuf] Wie ich den Drahtzieher hinter der Fernsteuerung aufspürte
    • 2019.04 [4hou] C&C-Fernsteuerungstool: Ares
    • 2019.04 [krebsonsecurity] Who’s Behind the RevCode WebMonitor RAT?
    • 2019.04 [freebuf] Analyse einer Monero-Mining- und RAT-Malware-Probe
    • 2019.04 [4hou] Analyse einer Monero-Mining- und RAT-Malware-Probe
    • 2019.04 [4hou] LimeRAT verbreitet sich in freier Wildbahn
    • 2019.04 [yoroi] LimeRAT spreads in the wild
    • 2019.04 [alexander] Week 6 Cyberattack Digest 2019 – ExileRAT trojan, Eskom Group, and others
    • 2019.03 [360] Tatoo-RAT-Backdoor vom Malware-Autor freiwillig eingereicht
    • 2019.03 [flashpoint] FIN7 Revisited: Inside Astra Panel and SQLRat Malware
    • 2019.03 [tencent] Mining-Malware zielt mit Brute-Force-Angriffen auf SQL-Server – Infektion führt zu Fernsteuerung
    • 2019.03 [paloaltonetworks] Cardinal RAT Sins Again, Targets Israeli Fin-T
    • 2019.03 [aliyun] Analyse: Wie JAVA-VBS zur RAT-Verbreitung eingesetzt wird
    • 2019.03 [malware] 2019-03-06 - QUICK POST: KOREAN MALSPAM PUSHES FLAWED AMMYY RAT MALWARE
    • 2019.03 [4hou] JAVA+VBS verbreitet RAT
    • 2019.03 [mcafee] JAVA-VBS Joint Exercise Delivers RAT
    • 2019.02 [dodgethissecurity] Reverse Engineering an Unknown RAT – Lets call it SkidRAT 1.0
    • 2019.02 [4hou] ExileRAT teilt sich C2-Infrastruktur mit LuckyCat
    • 2019.02 [freebuf] Xiaomi M365 Elektroroller von Hacking und Fernsteuerung bedroht
    • 2019.02 [myonlinesecurity] Fake Blockchain authentication update delivers Dark Comet RAT
    • 2019.02 [securityartwork] Case study: “Imminent RATs” (III)
    • 2019.02 [securityartwork] Case study: “Imminent RATs” (II)
    • 2019.02 [securityledger] ExileRAT Malware Targets Tibetan Exile Government
    • 2019.02 [securityartwork] Case study: “Imminent RATs” (I)
    • 2019.02 [talosintelligence] ExileRAT shares C2 with LuckyCat, targets Tibet
    • 2019.02 [0x00sec] Programming language for Remote Access Toolkit
    • 2019.01 [angelalonso] Fudcrypt: the service to crypt Java RAT through VBS scripts and Houdini malware
    • 2019.01 [yoroi] The Story of Manuel’s Java RAT
    • 2019.01 [0x00sec] RATs question. Long break
    • 2019.01 [aliyun] RAT-Bedrohungen mit AMP-Technologie analysieren
    • 2019.01 [360] Ausnutzung einer Schwachstelle in Marvell Avastar Wi-Fi zur Fernsteuerung von Geräten: Von Nullkenntnissen zur RCE-Ausnutzung (Teil 2)
    • 2019.01 [aliyun] Verbreitung von .Net RAT-Malware über MS Word-Dokumente
    • 2019.01 [tencent] Tencent PC Manager: „Big Grey Wolf“-RAT tarnt sich als „Clubmitglieder-Daten“
    • 2019.01 [360] Ausnutzung einer Schwachstelle in Marvell Avastar Wi-Fi zur Fernsteuerung von Geräten: Von Nullkenntnissen zur RCE-Ausnutzung (Teil 1)
    • 2019.01 [4hou] Verbreitung von .Net RAT-Malware über MS Word-Dokumente
    • 2019.01 [0x00sec] VPS or a VPN for a RAT?
    • 2019.01 [talosintelligence] What we learned by unpacking a recent wave of Imminent RAT infections using AMP
    • 2019.01 [fortinet] .Net RAT Malware Being Spread by MS Word Documents
    • 2019.01 [4hou] TA505 fügt seiner Waffenkammer neue ServHelper Backdoor und FlawedGrace RAT hinzu
    • 2019.01 [tencent] Browser-Entführung, Fernsteuerung, Video-View-Betrug – dieser Crack-Aktivator ist giftig!
    • 2019.01 [4hou] Adware tarnt sich als Spiele und Fernsteuerungs-Apps – infiziert 9 Millionen Google Play-Nutzer
    • 2019.01 [UltraHacks] Ozone RAT C++ | Hidden VNC [TUTORIAL VIDEO] | Ultra Hacks
    • 2019.01 [micropoor] Fortgeschrittene persistente Infiltration – Staffel 8: Demo ist eine Fernsteuerung
    • 2019.01 [tencent] Verdacht auf Gorgon-Gruppe: Gezielte Angriffe auf chinesische Außenhandelsbranche mit Azorult RAT
    • 2019.01 [4hou] JungleSec-Ransomware infiziert Opfer über IPMI-Fernsteuerungskonsole
    • 2019.01 [sans] Remote Access Tools: The Hidden Threats Inside Your Network
    • 2018.12 [freebuf] tRat: Ein neuer modularer RAT taucht in mehreren Spam-Kampagnen auf
    • 2018.12 [k7computing] Scumbag Combo: Agent Tesla and XpertRAT
    • 2018.12 [360] Flash 0day + Hacking Team RAT: Angriffskampagnen mit der neuesten Flash-0day-Lücke und zugehörige Analysen
    • 2018.12 [freebuf] Flash 0day + Hacking Team RAT: Angriffskampagnen mit der neuesten Flash-0day-Lücke und zugehörige Analysen
    • 2018.11 [4hou] tRat: Neuer modularer RAT
    • 2018.11 [proofpoint] tRat: Neue modulare Fernsteuerung, die in mehreren E-Mail-Kampagnen verteilt wird
    • 2018.11 [checkpoint] October 2018’s Most Wanted Malware: For The First Time, Remote Access Trojan Reaches Top 10 Threats | Check Point Software Blog
    • 2018.11 [checkpoint] October 2018’s Most Wanted Malware: For The First Time, Remote Access Trojan Reaches Global Threat Index’s Top 10
    • 2018.10 [DEFCONConference] DEF CON 26 CAR HACKING VILLAGE - Dan Regalado - Meet Salinas, 1st SMS commanded Car Infotainment RAT
    • 2018.10 [cybrary] “I smell a rat!” – AhMyth, not a Myth
    • 2018.10 [4hou] Wie RATs in der Industrie eingesetzt werden
    • 2018.10 [360] RAT missbraucht offizielle NetEase-Signatur
    • 2018.10 [ncsc] RATs, Mimikatz and other domestic pests
    • 2018.10 [infosecinstitute] Interview with RaT, the High Council President of SOLDIERX
    • 2018.10 [vulnerability0lab] Facebook Inc via Instagram Business - Remote Access Token Vulnerability (Original Facebook Video)
    • 2018.10 [securityledger] Episode 114: Complexity at Root of Facebook Breach and LoJax is a RAT You Can’t Kill
    • 2018.10 [sophos] IP EXPO Europe 2018: Sophos experts talk AI, privacy vs security, and RATs
    • 2018.09 [kaspersky] Threats posed by using RATs in ICS
    • 2018.09 [kaspersky] Industrial networks in need of RAT control
    • 2018.09 [securelist] Threats posed by using RATs in ICS
    • 2018.08 [traffic] [2018-08-22] Unknown->RigEK->AZORult->BabylonRAT
    • 2018.08 [freebuf] Hero RAT: Ein Telegram-basierter Android-Schädling
    • 2018.08 [4hou] Spam-Kampagne missbraucht SettingContent-ms zur Verbreitung von FlawedAmmyy RAT
    • 2018.08 [aliyun] Analyse des Telegram-basierten Android-Schädlings HeroRAT
    • 2018.08 [alienvault] Off-the-shelf RATs Targeting Pakistan
    • 2018.07 [k7computing] Weaponized.IQY: A Quest to Deliver the FlawedAmmyy RAT
    • 2018.07 [trendmicro] Spam Campaign Abusing SettingContent-ms Found Dropping Same FlawedAmmy RAT Distributed by Necurs
    • 2018.07 [k7computing] Weaponized.IQY: A Quest to Deliver the FlawedAmmyy RAT
    • 2018.07 [4hou] Hochentwickelter Parasite-RAT im Darknet aufgetaucht
    • 2018.07 [proofpoint] Parasite HTTP RAT cooks up a stew of stealthy tricks
    • 2018.07 [aliyun] Tiefgehende Analyse von Vermin RAThole
    • 2018.07 [proofpoint] TA505 Abusing SettingContent-ms within PDF files to Distribute FlawedAmmyy RAT
    • 2018.07 [welivesecurity] Vermin one of three RATs used to spy on Ukrainian government institutions
    • 2018.07 [freebuf] HeroRAT: Ein neuer Telegram-basierter Android-RAT
    • 2018.06 [heimdalsecurity] Security Alert: New Spam Campaign Delivers Flawed Ammyy RAT to Infect Victims’ Computers
    • 2018.06 [welivesecurity] HeroRAT: Telegram-basierter Android-RAT, geschrieben mit Xamarin-Framework
    • 2018.06 [4hou] Neueste technische Warnung der US-Regierung: Vorsicht vor zwei RATs und einem Wurm der nordkoreanischen Hackergruppe Hidden Cobra
    • 2018.06 [4hou] NavRAT nutzt Gipfeltreffen zwischen USA und Nordkorea als Köder für Angriffe auf Südkorea
    • 2018.06 [360] NavRAT nutzt US-Nordkorea-Gipfel als Köder für Angriffe auf Südkorea
    • 2018.05 [talosintelligence] NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea
    • 2018.05 [myonlinesecurity] Necurs delivering Flawed Ammy RAT via IQY Excel Web Query files
    • 2018.05 [freebuf] Geknackte Drupal-Sites zum Mining, RAT-Verbreitung und Spam-Versand genutzt
    • 2018.05 [andreafortuna] Malware VM detection techniques evolving: an analysis of GravityRAT
    • 2018.05 [360] GravityRAT: Zweijährige Entwicklung eines APT mit Ziel Indien
    • 2018.05 [pcsxcetrasupport3] A closer look at “NetSupport”(Rat) top 2 layers
    • 2018.05 [freebuf] Mythos-Legende: Ein RAT, der über den Verkauf von Accounts in WeChat-Gruppen verbreitet wird
    • 2018.04 [virusbulletin] GravityRAT malware takes your system's temperature
    • 2018.04 [360] Mythos-Legende: Über den Verkauf von Accounts in WeChat-Gruppen verbreiteter RAT
    • 2018.04 [talosintelligence] GravityRAT - The Two-Year Evolution Of An APT Targeting India
    • 2018.04 [UltraHacks] WebMonitor RAT - NO PORTFORWARD NEEDED + FREE VPN NEW
    • 2018.04 [4hou] Analyse eines RAT, der sich als Cheat-Tool für Spiele tarnt
    • 2018.04 [freebuf] Analyse eines RAT, der sich als Cheat-Tool für Spiele tarnt
    • 2018.04 [360] Analyse eines RAT, der sich als Cheat-Tool für Spiele tarnt
    • 2018.04 [4hou] Aufbau einer RAT-Infrastruktur mit DigitalOcean
    • 2018.04 [flashpoint] RAT Gone Rogue: Meet ARS VBS Loader
    • 2018.04 [lookout] mAPT ViperRAT Found in Google Play
    • 2018.04 [bitdefender] RadRAT: An all-in-one toolkit for complex espionage ops
    • 2018.04 [paloaltonetworks] Say “Cheese”: WebMonitor RAT Comes with C2-as-a-Service
    • 2018.04 [freebuf] Delphi-Hackerprogrammierung (Teil 3): Einfache Implementierung einer Fernsteuerung
    • 2018.04 [fireeye] Fake Software Update Abuses NetSupport Remote Access Tool
    • 2018.04 [freebuf] PowerShell-RAT: Ein Python-basierter Backdoor
    • 2018.03 [UltraHacks] Spynote v5.8 Android RAT | Tutorial | www.ultrahacks.org | Ultra Hacks
    • 2018.03 [360] TeleRAT: Erneute Entdeckung von Android-Malware, die Telegram zur Ausrichtung auf iranische Benutzer nutzt
    • 2018.03 [paloaltonetworks] TeleRAT: Another Android Trojan Leveraging Telegram’s Bot API to Target Iran
    • 2018.03 [4hou] Über ein Dutzend Sicherheitslücken in Samsung SmartCam: Fernsteuerung und Manipulation von Videobildern möglich
    • 2018.03 [360] Detaillierte Analyse der Coldroot RAT – einer plattformübergreifenden Backdoor für OS X
    • 2018.03 [freebuf] Schwarze Magie im Frontend: Fernsteuerung der Adressleiste
    • 2018.03 [broadanalysis] EiTest campaign Hoefler Text Pop-up delivers NetSupport Manager RAT
    • 2018.03 [leavesongs] Schwarze Magie im Frontend: Fernsteuerung der Adressleiste
    • 2018.03 [broadanalysis] Fake Flash update leads to NetSupport RAT
    • 2018.03 [broadanalysis] EiTest campaign Hoefler Text Pop-up delivers NetSupport Manager RAT
    • 2018.03 [4hou] HD und unzensiert! Spannender als ein Horrorfilm! Hören Sie den Schreckensgesang des „Doll“-RAT
    • 2018.03 [freebuf] HD und unzensiert! Spannender als ein Horrorfilm! Hören Sie den Schreckensgesang des „Doll“-RAT
    • 2018.03 [360] Nichts für Zartbesaitete! Spannender als ein Horrorfilm! Hören Sie den Schreckensgesang des „Doll“-RAT
    • 2018.02 [broadanalysis] Fake Flash update leads to NetSupport RAT
    • 2018.02 [broadanalysis] EiTest campaign Hoefler Text Pop-up delivers NetSupport Manager RAT
    • 2018.02 [myonlinesecurity] Fake DHL notification delivers some sort of Java RAT
    • 2018.02 [4hou] Neue AndroRAT-Variante nutzt veraltete Root-Lücke für Angriffe
    • 2018.02 [objective] Tearing Apart the Undetected (OSX)Coldroot RAT
    • 2018.02 [trendmicro] New AndroRAT Exploits Dated Privilege Escalation Vulnerability, Allows Permanent Rooting
    • 2018.02 [360] RAT legt raffinierte „Weiß-Schwarz“-Falle: Ziel sind Online-Großhändler
    • 2018.01 [broadanalysis] EiTest campaign Hoefler Text Pop-up delivers NetSupport Manager RAT
    • 2018.01 [4hou] Schwere Fernsteuerungslücke in Blizzard-Spielen betrifft Hunderte Millionen Nutzer
    • 2018.01 [riskiq] Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors
    • 2018.01 [freebuf] Analyse einer RAT-Probe, die eine Kombination aus der NDay-Lücke CVE-2017-11882 und der 0Day-Lücke CVE-2018-0802 nutzt
    • 2018.01 [broadanalysis] EiTest campaign Hoefler Text Pop-up delivers NetSupport Manager RAT
    • 2018.01 [netskope] Git Your RATs Here!
    • 2018.01 [redcanary] We Smell a RAT: Detecting a Remote Access Trojan That Snuck Past a User
    • 2018.01 [rsa] Malspam delivers BITTER RAT 01-07-2018
    • 2018.01 [freebuf] C#-Virus auf Mobilgeräten „wiederbelebt“: Nutzt bekannte Apps zur Kommunikation für Fernsteuerung und Datendiebstahl
    • 2017.12 [tencent] Analyse des Torchwood-RAT, der über CHM-Dateien verbreitet wird
    • 2017.12 [avlsec] C#-Virus auf Mobilgeräten „wiederbelebt“: Nutzt bekannte Apps zur Kommunikation für Fernsteuerung und Datendiebstahl
    • 2017.12 [broadanalysis] Fake Flash Player update delivers Net Support RAT
    • 2017.12 [netskope] TelegramRAT evades traditional defenses via the cloud
    • 2017.12 [4hou] Palo Alto Networks: UBoatRAT greift Ostasien an
    • 2017.12 [TechnoHacker] RATs in a Nutshell
    • 2017.11 [paloaltonetworks] UBoatRAT Navigates
    • 2017.11 [buguroo] New banking malware in Brazil - XPCTRA RAT ANALYSIS
    • 2017.11 [traffic] [2017-11-18] KaiXinEK->RAT
    • 2017.11 [freebuf] Analyse des Torchwood-RAT, der über CHM-Dateien verbreitet wird
    • 2017.11 [qq] Analyse des Torchwood-RAT, der über CHM-Dateien verbreitet wird
    • 2017.11 [TechnicalMujeeb] A-RAt exploit Tool Remote Access Android using Termux App.
    • 2017.11 [securityintelligence] RAT-Malware nutzt AutoIt-Skript zur Umgehung von Antiviren-Erkennung
    • 2017.11 [360] Powershell Empire zur Umgehung von AV für Fernsteuerung
    • 2017.10 [riskiq] New htpRAT Gives Complete Remote Control Capabilities to Chinese Threat Actors
    • 2017.10 [lookout] JadeRAT mobile surveillanceware spikes in espionage activity
    • 2017.10 [buguroo] RAT Protection for Banking Customers That Works
    • 2017.10 [cylance] Cylance vs. Hacker’s Door Remote Access Trojan
    • 2017.10 [malwarebytes] Ein „normales“ Word-Dokument lädt beim Öffnen automatisch eine bösartige RTF-Datei herunter (CVE-2017-8759), die dann die endgültige Nutzlast ausführt
    • 2017.10 [rsa] Malspam Delivers HWorm RAT October, 2017
    • 2017.09 [freebuf] Analyse und Rückverfolgung des „Bumblebee“-Mining-RAT (inkl. Autorenkommentar)
    • 2017.09 [intezer] Analyse neuer Varianten von Agent.BTZ/ComRAT (Teil 2)
    • 2017.09 [360] Analyse eines RAT, der die „EternalBlue“-Lücke ausnutzt
    • 2017.09 [UltraHacks] SilentBytes RAT 1.6.3c | Multi Administration Tool!
    • 2017.09 [freebuf] Die Heuschrecke fängt die Zikade – Geheimnisse hinter der kostenlosen Verbreitung des Cobian-RAT
    • 2017.09 [360] Wie man drahtlose Mäuse fernsteuert: Enthüllung der Maus-Hijacking-Interna
    • 2017.09 [4hou] „Phishing“-Plugin in der Praxis: So verwandle ich den Editor eines unvorsichtigen Entwicklers in eine Fernsteuerung
    • 2017.09 [fortinet] Analyse eines überarbeiteten RAT in APT-Kampagnen gegen vietnamesische Organisationen
    • 2017.09 [TechnoHacker] Arcom RAT: Is It Worth $3000?
    • 2017.08 [lookout] Android-RAT xRAT
    • 2017.08 [paloaltonetworks] Updated KHRAT Malware Used in Cambodia
    • 2017.08 [JackkTutorials] How to make a HTTP RAT (#3)
    • 2017.08 [freebuf] RAT nutzt „White-Label“ aus: Enthüllung des Diebstahls hinter gefälschten Crack-Tools
    • 2017.08 [4hou] RAT nutzt „White-Label“ aus: Enthüllung des Diebstahls hinter gefälschten Crack-Tools
    • 2017.08 [fortinet] A Quick Look at a New KONNI RAT Variant
    • 2017.08 [freebuf] Wie man Photoshop in ein Fernsteuerungstool (RAT) umwandelt
    • 2017.08 [n0where] Koadic C3 COM Command & Control – JScript RAT
    • 2017.08 [cylance] Threat Spotlight: KONNI – A Stealthy Remote Access Trojan
    • 2017.08 [cylance] Cylance vs. KONNI RAT
    • 2017.08 [intezer] New Variants of Agent.BTZ/ComRAT Found: The Threat That Hit The Pentagon In 2008 Still Evolving; Part 1/2
    • 2017.08 [rsa] Malspam delivers Xtreme RAT 8-1-2017
    • 2017.07 [CodeColorist] How to turn Photoshop into a remote access tool
    • 2017.07 [pentestmag] Stitch – a Python written cross platform RAT
    • 2017.07 [freebuf] Schwere Sicherheitslücke in internationaler Version des Xiaomi Ninebot Mini: Angreifer können Fersteuerung übernehmen
    • 2017.07 [pentestingexperts] Hacking Android Smart Phone Using AhMyth Android RAT
    • 2017.07 [JackkTutorials] How to make a HTTP RAT (#2)
    • 2017.07 [ringzerolabs] Bladabindi RAT
    • 2017.07 [krebsonsecurity] Who is the GovRAT Author and Mirai Botmaster ‘Bestbuy’?
    • 2017.07 [JackkTutorials] How to make a HTTP RAT (#1)
    • 2017.06 [freebuf] Der große Meister des „White-Label“: Ein neuer RAT mit Verwandlungstrick
    • 2017.06 [pediy] [Original] Verhaltensanalyse eines RAT
    • 2017.06 [ColinHardy] JavaScript that drops a RAT - Reverse Engineer it like a pro
    • 2017.06 [4hou] Der große Meister des „White-Label“: Ein neuer RAT mit Verwandlungstrick
    • 2017.06 [360] Der große Meister des „White-Label“: Ein neuer RAT mit Verwandlungstrick
    • 2017.06 [freebuf] Metasploit-Experiment: Erstellung eines AV-umgehenden Payloads + Fernsteuerung eines beliebigen „externen“ Hosts
    • 2017.06 [cylance] Cylance vs. FF-Rat Malware
    • 2017.06 [cylance] Threat Spotlight: Breaking Down FF-Rat Malware
    • 2017.06 [alienvault] MacSpy: Erste MaaS-Malware (Malware-as-a-Service) für die Mac-Plattform
    • 2017.05 [TechnoHacker] How to check if you're infected with a RAT in 10 seconds
    • 2017.05 [freebuf] VIP unter den RATs: Diebstahl von Online-Shopping-Konten zum Kauf virtueller Geschenkkarten
    • 2017.05 [pediy] [Original] Von Null an: Analyse eines klassischen infizierenden RAT
    • 2017.05 [4hou] VIP unter den RATs: Diebstahl von Online-Shopping-Konten zum Kauf virtueller Geschenkkarten
    • 2017.05 [sec] VIP unter den RATs: Diebstahl von Online-Shopping-Konten zum Kauf virtueller Geschenkkarten
    • 2017.05 [360] VIP unter den RATs: Diebstahl von Online-Shopping-Konten zum Kauf virtueller Geschenkkarten
    • 2017.05 [aliyun] FlexiSpy For Android Remote Control Backdoor
    • 2017.05 [UltraHacks] Imminent Monitor RAT setup & New update review 2017
    • 2017.05 [TechnoHacker] How to spread your RAT
    • 2017.05 [esecurityplanet] Shodan Partners with Recorded Future to Detect Botnets and RATs
    • 2017.04 [alienvault] The Felismus RAT: Powerful Threat, Mysterious Purpose
    • 2017.04 [4hou] Sicherheitslücke in über 20 Linksys-Routern – Fernsteuerung möglich
    • 2017.04 [freebuf] Vorsicht, Android-RAT (Spynote) wurde aktualisiert …
    • 2017.04 [paloaltonetworks] Cardinal RAT Active for Over
    • 2017.04 [jpcert] RedLeaves - Malware Based on Open Source RAT
    • 2017.03 [TechnoHacker] What's the difference between http botnets and RATs?
    • 2017.03 [paloaltonetworks] Trochilus and New MoonWind RATs Used In Attack Against Thai Organizations
    • 2017.03 [fireeye] WMImplant – A WMI Based Agentless Post-Exploitation RAT Developed in PowerShell
    • 2017.03 [4hou] Nachwirkungen des CIA-Vorfalls: Über 300 Cisco-Switches betroffen, ein 0Day ermöglicht Fernsteuerung
    • 2017.03 [secist] Python-basiertes Remote-Administration-Tool (RAT) – Stitch
    • 2017.03 [trendmicro] MajikPOS: Eine Kombination aus POS-Malware und RAT
    • 2017.03 [4hou] Proton RAT nutzt 0Day-Lücke für neue Variante – ab 1200 US-Dollar erhältlich
    • 2017.02 [UltraHacks] SilentBytes RAT [beta] Windows 10 || PROMOTION ||
    • 2017.02 [UltraHacks] SilentBytes RAT Linux Ubuntu || PROMOTION ||
    • 2017.02 [UltraHacks] SilentBytes RAT 1.1 [BETA] Mac OS X || PROMOTION ||
    • 2017.02 [lookout] ViperRAT: The mobile APT targeting the Israeli Defense Force that should be on your radar
    • 2017.02 [talosintelligence] Go RAT, Go! AthenaGo points “TorWords” Portugal
    • 2017.02 [netskope] Decoys, RATs, and the Cloud: The growing trend
    • 2017.01 [malwarebytes] Mobile Menace Monday: AndroRAT Evolved
    • 2017.01 [malwarebytes] From a fake wallet to a Java RAT
    • 2016.12 [TechnoHacker] How to remotely execute a RAT on someone's PC
    • 2016.12 [cyber] The Kings In Your Castle Part 4 – Packers, Crypters and a Pack of RATs
    • 2016.11 [] Linux-RAT-Analyse
    • 2016.11 [] Linux-RAT-Analyse
    • 2016.11 [f] A RAT For The US Presidential Elections
    • 2016.11 [fidelissecurity] Down the H-W0rm Hole with Houdini's RAT
    • 2016.11 [4hou] Auf Pastebin gehosteter RAT kann System-BSOD verursachen
    • 2016.10 [malwarebytes] Get your RAT on Pastebin
    • 2016.10 [8090] Huawei P9 Fingerabdrucksensor geknackt, Steckdosen-Fernsteuerung per Tweet – Sicherheitsprobleme bei Smart-Home-Produkten
    • 2016.10 [sentinelone] GovRAT is Not New
    • 2016.10 [UltraHacks] [$25] Imment Monitor RAT setup
    • 2016.09 [securelist] TeamXRat: Brazilian cybercrime meets ransomware
    • 2016.09 [freebuf] RAT mit Account-Diebstahl tarnt sich als 850Game
    • 2016.09 [jimwilbur] DroidJack – A Quick Look at an Android RAT
    • 2016.09 [360] RAT mit Account-Diebstahl tarnt sich als 850Game
    • 2016.09 [countercept] Do you smell a rat?
    • 2016.09 [countercept] Do you smell a rat?
    • 2016.09 [freebuf] You dirty RAT: „Dog-Eat-Dog“ in der Cyberkriminalität
    • 2016.08 [fortinet] German Speakers Targeted by SPAM Leading to Ozone RAT
    • 2016.08 [freebuf] WeChat-Schwachstelle für Remote Code Execution – Fernsteuerung möglich
    • 2016.08 [trustlook] Trustlook Discovers a Remote Administration Tool (RAT) Android Malware
    • 2016.08 [id] XRat, Team, Corporacao
    • 2016.08 [f] NanHaiShu: RATing the South China Sea
    • 2016.07 [malwarenailed] Luminosity RAT - Re-purposed
    • 2016.07 [360] RAT mit legaler Tarnung – Tiefgehende Analyse von Game564
    • 2016.07 [fidelissecurity] Chasing Down RATs with Barncat
    • 2016.07 [n0where] Python Remote Access Tool: Ares
    • 2016.07 [360] H-WORM: Einfacher und aktiver RAT
    • 2016.06 [duo] Protecting Remote Access to Your Computer: RDP Attacks and Server Credentials for Sale
    • 2016.06 [cybereason] Permission to Execute: The Incident of the Signed and Verified RAT
    • 2016.06 [8090] Analyse eines JavaScript-RAT für gezielte Angriffe
    • 2016.06 [hackingarticles] HTTP RAT Tutorial for Beginners
    • 2016.06 [avlsec] Falsche Nutzung bekannter Apps zur Einschleusung bösartiger Module – „Wolf im Schafspelz“! Warnung vor WarThunder-RAT
    • 2016.06 [cysinfo] Hunting APT RAT 9002 In Memory Using Volatility Plugin
    • 2016.06 [f] Qarallax RAT: Spying On US Visa Applicants
    • 2016.06 [qq] RAT nutzt Windows-Systemdatei-Lücke für Angriffe
    • 2016.06 [samvartaka] Dead RATs: Exploiting malware C2 servers
    • 2016.05 [freebuf] Tiefgang: RAT Poison Ivy beginnt Myanmar und andere asiatische Länder zu quälen
    • 2016.05 [trendmicro] Lost Door RAT: Accessible, Customizable Attack Tool
    • 2016.04 [pentestpartners] RATing through the Steam Workshop
    • 2016.04 [freebuf] DameWare Mini Remote Control-Schwachstelle (CVE-2016-2345): Fernsteuerung im Handumdrehen
    • 2016.04 [paloaltonetworks] New Poison Ivy RAT Variant Targets Hong Kong Pro-Democracy
    • 2016.04 [sentinelone] Teaching an old RAT new tricks
    • 2016.04 [itsjack] RAT Threat Intelligence – A Very Simple Manual Technique
    • 2016.03 [TechnoHacker] How to port forward for any program and how to setup a DNS for RATs
    • 2016.03 [malwarebytes] Latest Steam Malware Shows Signs of RAT Activity
    • 2016.03 [freebuf] Wie man drahtlose Mäuse fernsteuert: Enthüllung der mouseJack-Interna
    • 2016.03 [malwarebytes] This Steam Scam is a Rat Race
    • 2016.03 [itsjack] Imminent Monitor 4 RAT Analysis – Further Into The RAT
    • 2016.02 [TechnoHacker] How to get rid of a RAT [Very in depth]
    • 2016.02 [brindi] Advanced Techniques for Detecting RAT Screen Control
    • 2016.02 [mindedsecurity] RAT WARS 2.0: Advanced Techniques for Detecting RAT Screen Control
    • 2016.01 [fidelissecurity] Introducing Hi-Zor RAT
    • 2016.01 [alienvault] Trochilus RAT: Invading your Sandbox
    • 2016.01 [itsjack] Imminent Monitor 4 RAT Analysis – A Glance
    • 2016.01 [freebuf] Analysebericht zum „Shadow Thief“-RAT
    • 2016.01 [] Linux-RAT-Analyse
    • 2016.01 [ensilo] Cyber-Security in 120 Secs: 0-days, and a new RAT targeting APJ
    • 2016.01 [TechnoHacker] How to use all of Xtreme RAT's features
    • 2016.01 [freebuf] Eine Analyse des JSocket-RAT
    • 2015.12 [paloaltonetworks] BBSRAT Attacks Targeting Russian Organizations Linked to Roam
    • 2015.12 [welivesecurity] Europol makes 12 arrests in Remote Access Trojan crackdown
    • 2015.11 [360] Tiefe Ermittlungen zum Drahtzieher des „Big Grey Wolf“-RAT
    • 2015.11 [cylance] Cylance vs. GlassRAT
    • 2015.11 [rsa] Detecting GlassRAT using Security Analytics and ECAT
    • 2015.11 [freebuf] KillerRat: Ägyptischer Hacker entwickelt neuen Windows-RAT
    • 2015.11 [freebuf] Nachfolgendes Malware-Event auf BT Paradise: Analyse des „Big Grey Wolf“-RAT und Ermittlungen zum Drahtzieher
    • 2015.11 [360] Analyse des „Big Grey Wolf“-RAT und Ermittlungen zum Drahtzieher
    • 2015.11 [freebuf] Heißverkauftes Killertool GovRAT: Malware-Plattform mit digitaler Signatur
    • 2015.11 [duo] Criminals Leverage Remote Access to Patient Data Applications
    • 2015.11 [fidelissecurity] A Stalker’s Best Friend: Inside JSocket’s Android Remote Access Tool Builder
    • 2015.10 [threatmetrix] How Contextual Fraud Prevention Can Turn Banks into RAT (Remote Access Trojan) Catchers
    • 2015.10 [deepsec] DeepSec Talk: Got RATs? Enter Barn Cat (OSint)
    • 2015.10 [360] Alternative Fernsteuerung: Trojaner nutzt kommerzielle Fernwartungssoftware zur versteckten Ausführung
    • 2015.10 [freebuf] Alternative Fernsteuerung: Trojaner nutzt kommerzielle Fernwartungssoftware zur versteckten Ausführung
    • 2015.10 [hackingarticles] Hack Android Devices using Omni RAT
    • 2015.10 [duo] Remote Access Trojan (RAT) Targets Windows Environments
    • 2015.09 [trustwave] Quaverse RAT: Remote-Access-as-a-Service
    • 2015.09 [freebuf] Analyse einer DoS-Schwachstelle im VNC-Fernsteuerungstool
    • 2015.09 [freebuf] Schönheit alter Backdoors: Fünf Retro-Fernsteuerungstools (mit Download)
    • 2015.09 [kaspersky] A layman’s dictionary: RAT
    • 2015.08 [sentinelone] The 7 ‘Most Common’ RATS In Use Today
    • 2015.08 [rsa] Detecting XtremeRAT variants using Security Analytics

    Read more

    Tool herunterladen