#BaDRAT

Malware/Tool

2023-01-04 • LABScon Replay | InkySquid: The Missing Arsenal

BaDRAT is the name used by one research team for the same macOS malware that ESET named CloudMensis; the researchers assessed it as a macOS version of RokRAT. It was discussed in the context of InkySquid, also known as APT37 or ScarCruft, a North Korean threat actor associated with spear phishing, watering holes, and exploitation of known vulnerabilities. A preceding downloader contained a pCloud API key, retrieved the final BaDRAT stage from pCloud, and dropped a persistence file implemented as a conventional macOS daemon. The downloader also retained unused code for a public 2017 privilege-escalation exploit.

Tagged Reports

« Back