Also known as: McRAT, Hydraq, HOMEUNIX
No AI analysis yet.
9002 RAT is a Remote Access Tool typically observed to be used by an APT to control a victim's machine. It has been spread over via zero day exploits (e.g. targeting Internet Explorer) as well as via email attachments. The infection chain starts by opening a .LNK (an OLE packager shell object) that executes a Powershell command. Attributed to: Aurora Panda, APT31, Group 27.