#EarlyRat

Malware/Tool

2023-06-28 • Andariel’s silly mistakes and a new malware family

EarlyRat is a relatively simple remote access trojan written with the PureBasic framework and associated with Andariel under the Lazarus umbrella. Observed delivery involved a Skype link to a ZIP archive containing a malicious document that impersonated Microsoft messaging and persuaded users to enable macros. The macro dropped EarlyRat, moved it into the Windows Startup folder as WHealthScanner.exe for persistence, and executed it. EarlyRat collects system information and sends it to command-and-control using Base64 encoding and rolling XOR keyed by a machine identifier. Its principal capability is command execution; observed commands gathered system, network-interface, connection, task, and process information.

Tagged Reports

« Back