#CabbageRAT

Malware/Tool

2020-09-30 • UNVEILING THE CRYPTOMIMIC

CabbageRAT, also called CageyChameleon, is a remote-access Trojan used in fake-meeting attacks against cryptocurrency and Web3 targets. Windows variants written in VBS collect host information, enumerate processes and Chrome extensions, exfiltrate data, and retrieve Base64-encoded, XOR-encrypted payloads for in-memory or on-disk execution. One variant persists through a shortcut in the Windows Startup folder. A related Linux ELF build uses HTTP POST, gathers system and network details, downloads and decrypts later stages, and executes them from a temporary directory. UNC1069 delivered these variants through ClickFix-style meeting prompts.

Tagged Reports

« Back