Skip to content

Add RAT family detection rules (FleetAgent, XWorm, Remcos, Quasar/NjR…#458

Open
PixelatedContinuum wants to merge 1 commit intoYara-Rules:masterfrom
PixelatedContinuum:batch3-rat-families
Open

Add RAT family detection rules (FleetAgent, XWorm, Remcos, Quasar/NjR…#458
PixelatedContinuum wants to merge 1 commit intoYara-Rules:masterfrom
PixelatedContinuum:batch3-rat-families

Conversation

@PixelatedContinuum
Copy link
Copy Markdown

…AT, Pulsar, PoetRAT)

New detection coverage for 6 RAT families, several of which have zero existing coverage in the repository.

Rules cover:

  • RAT_FleetAgent.yar: FleetAgentFUD WebSocket RAT + FleetAgentAdvanced dropper with quad-persistence mechanism (7 rules)
  • RAT_XWorm.yar: XWorm RAT v5.x (agent_xworm.exe) and v2.4.0 (agent_xworm_v2.exe) with AgentSec authentication pattern (9 rules)
  • RAT_Remcos_OpenDirectory.yar: Remcos RAT open directory campaign (109.230.231.37) with VB6 dropper and UAC bypass persistence (6 rules)
  • RAT_QuasarNjRAT_DualRAT.yar: Dual infection of Quasar RAT + NjRAT/XWorm with triple persistence mechanism (4 rules)
  • RAT_Pulsar.yar: Pulsar RAT critical variant detection (1 rule)
  • RAT_PoetRAT_Agent.yar: PoetRAT compiled Golang agent.exe - extends existing PoetRAT Python/doc coverage to compiled variant (3 rules)

Reference: https://pixelatedcontinuum.github.io/Threat-Intel-Reports/

…AT, Pulsar, PoetRAT)

New detection coverage for 6 RAT families, several of which have zero
existing coverage in the repository.

Rules cover:
- RAT_FleetAgent.yar: FleetAgentFUD WebSocket RAT + FleetAgentAdvanced
  dropper with quad-persistence mechanism (7 rules)
- RAT_XWorm.yar: XWorm RAT v5.x (agent_xworm.exe) and v2.4.0
  (agent_xworm_v2.exe) with AgentSec authentication pattern (9 rules)
- RAT_Remcos_OpenDirectory.yar: Remcos RAT open directory campaign
  (109.230.231.37) with VB6 dropper and UAC bypass persistence (6 rules)
- RAT_QuasarNjRAT_DualRAT.yar: Dual infection of Quasar RAT + NjRAT/XWorm
  with triple persistence mechanism (4 rules)
- RAT_Pulsar.yar: Pulsar RAT critical variant detection (1 rule)
- RAT_PoetRAT_Agent.yar: PoetRAT compiled Golang agent.exe - extends
  existing PoetRAT Python/doc coverage to compiled variant (3 rules)

Reference: https://pixelatedcontinuum.github.io/Threat-Intel-Reports/
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant