#TutorialRAT
Malware/Tool
TutorialRAT is a remote-access tool used in a multistage APT43 campaign described as an extension of BabyShark activity. The operation targeted Korean recipients with responsive spear-phishing themes such as policy meetings, advisory sessions, surveys, lectures, and payment forms. Attackers began with legitimate-looking email, embedded an archive in HTML disguised as government secure mail, and delivered a benign decoy document alongside a malicious Windows shortcut. The campaign used the legitimate Dropbox cloud-storage service as part of its multistage attack chain and command infrastructure, an approach intended to move activity outside ordinary threat-monitoring scope and evade signature-based antivirus detection.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days