#TutorialRAT

Malware/Tool

2024-04-17 • APT43 배후의 다단계 드롭박스 명령과 TutorialRAT

TutorialRAT is a remote-access tool used in a multistage APT43 campaign described as an extension of BabyShark activity. The operation targeted Korean recipients with responsive spear-phishing themes such as policy meetings, advisory sessions, surveys, lectures, and payment forms. Attackers began with legitimate-looking email, embedded an archive in HTML disguised as government secure mail, and delivered a benign decoy document alongside a malicious Windows shortcut. The campaign used the legitimate Dropbox cloud-storage service as part of its multistage attack chain and command infrastructure, an approach intended to move activity outside ordinary threat-monitoring scope and evade signature-based antivirus detection.

Tagged Reports

« Back