Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware RunningRAT

RunningRAT

TLP:CLEAR
Family

AI Analysis

· 7 hours ago

Executive Summary

RunningRAT is a Windows remote access tool deployed during the 2018 PyeongChang Winter Olympics in a campaign alongside Gold Dragon and Brave Prince. It provides adversaries with persistent control, keylogging, and file‑exfiltration capabilities, indicating its use by state‑sponsored actors targeting high‑value sports organizations.

Enhanced Description

RunningRAT is a Windows‑based remote access tool that first appeared during the 2018 PyeongChang Winter Olympics in association with other sophisticated campaigns such as Gold Dragon and Brave Prince. It was identified by McAfee as part of the operations aimed at compromising athletes, coaching staff and associated infrastructure. As a true backdoor, RunningRAT provides adversaries with persistent, stealthy control over infected systems. The malware facilitates remote command execution, keylogging, screenshot capture, file transfer, and can spawn additional malicious components. Its presence in Olympic‑related networks indicates its use by state‑aligned threat actors targeting sensitive sports data. The tool’s architecture suggests modular code designed for evasion: it utilizes standard Windows services, scheduled tasks, and registry persistence mechanisms while hiding processes and files from most native security tools. Its linkage with other high‑profile campaigns points to a shared operational framework or shared code base among the adversary groups responsible for these attacks.

Key Capabilities

  • Remote command execution
  • Keylogging
  • Screenshot capture
  • File upload/download
  • Persistence via scheduled tasks or registry keys
  • Process injection
  • Stealth mechanisms (hidden files/processes)

ATT&CK Techniques

T1059
T1105
T1082
T1053
T1070

Recommended Actions

  • Deploy behavioral detection rules targeting RAT command and control traffic on uncommon ports
  • Implement strict perimeter controls to block inbound remote‑access protocols
  • Enable anomaly monitoring for scheduled task creation on endpoints
  • Apply least privilege principles to limit Remote Desktop use

Suggested Tags

remote access tool
RAT
windows malware
Olympic related threat activity
state-sponsored actor
athlete target

Confidence Assessment

The analysis is based solely on a short description and association with other campaigns. No executable sample, hash, or detailed technical indicator has been provided, limiting the depth of capability insight. Further investigation of artifacts such as file hashes, network signatures, and code samples would increase confidence.

Description

RunningRAT is a remote access tool that appeared in operations surrounding the 2018 Pyeongchang Winter Olympics along with Gold Dragon and Brave Prince. (Citation: McAfee Gold Dragon)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.