#CollectionRAT
Malware/Tool
2023-08-24 • Lazarus Group's infrastructure reuse leads to discovery of new malware
CollectionRAT is a remote access trojan used by the North Korean state-sponsored Lazarus Group. It provides standard RAT functionality, including execution of arbitrary commands on an infected system. Cisco Talos discovered it in a campaign where Lazarus exploited CVE-2022-47966 in ManageEngine ServiceDesk and deployed multiple threats, including QuiteRAT. Analysis indicates that CollectionRAT may be connected to Jupiter, also called EarlyRAT, a malware family attributed to Andariel, a subgroup within the broader Lazarus threat actor umbrella. The campaign also reflected Lazarus Group’s continued reuse of previously documented infrastructure and tactics.
-
2
Tagged Reports
-
2
Unique Authors
-
383
Active Days