#M2RAT
Malware/Tool
2023-02-14 • 스테가노그래피 기법 사용한 한글(HWP) 악성코드 : RedEyes(ScarCruft)
M2RAT, also called Map2RAT, is a Windows backdoor used by the RedEyes group and injected into explorer.exe. It receives commands through HTTP POST requests, identifies hosts by MAC address, and stores an XOR-encoded identifier in the user registry. Its functions include keylogging, screen capture, process execution and termination, and theft of documents and audio files. Captured keystrokes and screenshots are sent directly to the server rather than stored locally, reducing forensic traces on the victim system.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days