#EarlyRat
Malware/Tool
EarlyRat is a relatively simple remote access trojan written with the PureBasic framework and associated with Andariel under the Lazarus umbrella. Observed delivery involved a Skype link to a ZIP archive containing a malicious document that impersonated Microsoft messaging and persuaded users to enable macros. The macro dropped EarlyRat, moved it into the Windows Startup folder as WHealthScanner.exe for persistence, and executed it. EarlyRat collects system information and sends it to command-and-control using Base64 encoding and rolling XOR keyed by a machine identifier. Its principal capability is command execution; observed commands gathered system, network-interface, connection, task, and process information.
-
2
Tagged Reports
-
2
Unique Authors
-
77
Active Days