#StarshellRAT

Malware/Tool

2026-01-22 • To the past and beyond: Andariel’s latest arsenal and cyberattacks

StarshellRAT is one of three previously undocumented remote access trojans that WithSecure attributed to Andariel while investigating two attacks involving enterprise resource planning software. The same ERP product had been targeted by Andariel in 2017 and was assessed as almost certainly targeted again in 2024. Researchers also identified a staging server used by the group and recovered additional artifacts related to both attacks from it. The broader operations combined new and older tooling, including PrintSpoofer and PetitPotato for privilege escalation and bring-your-own-vulnerable-driver activity intended to kill antivirus or endpoint-detection products.

Tagged Reports

« Back