Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Packrat

Description

A threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists, journalists, politicians and public figures in various Latin American countries. The threat actor, dubbed Packrat based on its preference for remote access Trojans (RATs) and because it has used the same infrastructure for several years, has been analyzed by Citizen Lab researchers John Scott-Railton, Morgan Marquis-Boire, and Claudio Guarnieri, and Cyphort researcher Marion Marschalek, best known for her extensive analysis of state-sponsored threats.

AI Analysis

· 1 week ago

Executive Summary

Packrat, a long-active threat actor targeting individuals in Latin America, primarily uses malware, phishing, and disinformation tactics. The group has been operational for at least seven years, focusing on activists, journalists, politicians, and public figures. Their activities suggest a strategic focus on influencing political dynamics and gathering sensitive information.

Goals & Targeting

Packrat's strategic objectives appear to be tied to political manipulation, information gathering, and undermining the credibility of targeted individuals or institutions. The group's targeting profile focuses on individuals with high public visibility or influence, such as journalists, politicians, and activists, particularly in Latin American countries. This suggests a desire to shape public opinion, disrupt governance, or gain access to sensitive information.

Enhanced Description

Packrat is a sophisticated cyber threat actor that has operated for over seven years, primarily targeting high-profile individuals in Latin America. The group specializes in using remote access Trojans (RATs), phishing campaigns, and disinformation tactics to compromise its victims. Packrat's activities have been extensively studied by researchers such as Citizen Lab and Cyphort, who have identified the group's long-term use of stationary infrastructure and its focus on politically sensitive targets. The threat actor's campaigns often involve spear-phishing emails with malicious attachments or links, aiming to infect devices and establish persistent access for surveillance or data exfiltration. Packrat’s operations demonstrate a high level of operational security and persistence, making it a significant concern for governments, media organizations, and activists in the region.

Key Capabilities

  • Use ofRemote Access Trojans (RATs)
  • Spear-phishing campaigns with malicious attachments
  • Disinformation tactics
  • Long-term infrastructure persistence
  • Targeted malware deployment

MITRE ATT&CK Tactics

Collection
Exfiltration
Espionage

ATT&CK Techniques

T1076
T1534
T1207

Software / Tooling

Packrat Remote Access Trojan
Cobalt Strike (linked to similar campaigns)
Custom malware

Campaigns & Victims

Packrat has demonstrated a consistent operational pattern over the years, with a focus on long-term campaigns and targeted attacks. The group's use of stationary infrastructure and persistent access techniques indicates a patient and methodical approach. Notable past operations include numerous phishing campaigns targeting activists and public figures in Ecuador and other Latin American countries. Packrat's ability to remain active for over seven years underscores its resilience and operational effectiveness.

IOC Patterns

  • Spear-phishing emails with malicious Office attachments
  • Malware-infected domains such as daynews.sytes.net and taskmgr.serveftp.com
  • MD5 hashes linked to their malware payloads (e.g., ea7bcf58a4ccdecb0c64e56b9998a4ac)
  • Cobalt Strike-like C2 domains

Recommended Actions

  • Implement rigorous user training on phishing and social engineering tactics
  • Monitor network traffic for known Packrat-related domains and IP addresses
  • Use endpoint detection and response (EDR) tools to detect RAT activity
  • Adopt strong email filtering solutions to block malicious attachments
  • Perform regular security audits to identify potential compromises

Suggested Tags

APT
Latin America
espionage
disinformation

Confidence Assessment

There is high confidence in Packrat's existence and operational patterns due to multiple studies by reputable researchers. However, gaps remain regarding the group's precise motivations, exact membership, and full range of capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 9 URL 8 SHA-256 Hash 1 SHA-1 Hash 2

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

122

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Latin America
espionage
disinformation

Details

Type
Criminal
Confidence
70%
Added
May 6, 2026
STIX ID
threat-actor--fe344665-d153-4d31-a32a-1509efde1ca7
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.