#MagicRAT
Malware/Tool
MagicRAT is a remote access trojan developed and operated by the Lazarus APT group, with reporting attributing it to that North Korean state-sponsored actor at moderate to high confidence. Lazarus deployed it after exploiting vulnerabilities in publicly exposed VMware Horizon platforms, using the resulting access to establish footholds in enterprise networks. The implant was built with the Qt Framework, a choice reported as complicating human analysis and automated heuristic or machine-learning detection while also offering cross-platform capabilities. The campaign overlapped in command-and-control and payload-hosting infrastructure with activity described in a CISA advisory and also involved other Lazarus implants, including TigerRAT, VSingle, and YamaBot. MITRE ATT&CK S1182.
-
4
Tagged Reports
-
2
Unique Authors
-
576
Active Days