#BlackRAT

Malware/Tool

2023-11-10 • 자산 관리 프로그램을 악용한 공격 정황 포착 (Andariel 그룹)

BlackRAT, also called ValidAlpha, is a custom Go backdoor used by Onyx Sleet against organizations in the energy, defense, and engineering sectors. It gives operators remote access by launching a command shell and can run arbitrary files, list directory contents, download files, and capture screenshots. Microsoft observed the family in global targeting from at least 2023 and identified a development-path string referencing “Black” and a Go client, consistent with the reported implementation.

Tagged Reports

« Back