Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TeamXRat

Also known as: CorporacaoXRat, CorporationXRat

AI Analysis

· 1 week ago

Executive Summary

TeamXRat is an unidentified cyber threat actor observed leveraging remote access trojans (RAT) for data exfiltration and surveillance activities. The group primarily targets corporate environments across Latin America, employing sophisticated tactics to maintain persistence and evade detection.

Goals & Targeting

TeamXRat's strategic objectives likely include corporate espionage and data theft, targeting sectors with sensitive information that could be monetized or leveraged strategically. The group's geographic focus on Latin America suggests they may have regional interests or operational capabilities concentrated in this area, potentially aligning with organized crime networks or financially motivated actors seeking to exploit local corporate environments.

Enhanced Description

TeamXRat, also known as CorporacaoXRat or CorporationX RAT, is a cyber threat actor primarily recognized for their use of remote access trojans (RATs) such as Grine and Cobalt Strike. The group has been observed in activities since 2018, targeting corporate sectors, including finance, healthcare, and telecommunications, across Latin America. Their primary modus operandi involves spear-phishing campaigns with malicious Office documents as payloads, followed by lateral movement via RDP and scheduled task persistence techniques. While not conclusively tied to any specific campaign name, their operational tactics suggest a focus on corporate espionage or data exfiltration for financial gain or competitive advantage.

Key Capabilities

  • Remote Access Trojans (RATs) such as Grine, Cobalt Strike
  • Spear-phishing emails with malicious Office documents
  • Persistence techniques including registry and fileless malware injection
  • Lateral movement via RDP and scheduled tasks

MITRE ATT&CK Tactics

Initial Access
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059.003
T1055
T1486
T1047
T1546
T1567.004
T1567.005

Software / Tooling

Grine RAT
Cobalt Strike
Custom remote access tools

Campaigns & Victims

TeamXRat has been observed in multiple campaigns since at least 2018, targeting corporate environments across Latin America. Their activities include spear-phishing email campaigns distributing malicious Office documents as payloads, followed by post-compromise activities such as lateral movement via RDP and the deployment of persistent backdoors. While specific campaign details are sparse, their operational consistency suggests a focused effort to infiltrate targeted organizations for prolonged periods. Notable past operations have included the use of fast-flux domains for command-and-control infrastructure and encrypted payload delivery, though exact campaign names or operational specifics remain unclear.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • RDP brute-force attempts
  • Scheduled task persistence techniques
  • Registry-based malware injection
  • C2 communication over fast-flux domains

Recommended Actions

  • Implement strong email filtering and DMARC policies to block phishing emails
  • Monitor network traffic for signs of C2 activity (e.g., unusual DNS queries)
  • Segment critical systems from less secure perimeters
  • Regularly audit and patch RDP services
  • Enhance user training on recognizing phishing attempts

Suggested Tags

APT
cybercrime
espionage
malware
Latin America

Confidence Assessment

Low confidence due to limited公开 information available on TeamXRat's precise motivations, historical operations, and exact targeting criteria. While their TTPs are relatively well-documented, the lack of clear attribution or campaign specifics leaves uncertainty around their broader objectives and capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
APT
cybercrime
espionage
malware
Latin America

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.