Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Innaput Actors Utilize Remote Access Trojan Since 2016, Presumably Targeting Victim Files

released on 2018-04-05 @ 06:44:37 PM
ASERT recently identified a campaign targeting commercial manufacturing in the US and potentially Europe in late 2017. The threat actors used phishing and downloader(s) to install a Remote Access Trojan (RAT) ASERT calls InnaputRAT on the target’s machine. The RAT contained a series of commands that includes machine profiling and the ability to exfiltrate documents from the victims’ machines. We believe this activity ties to a specific set of actors with defined campaign goals. We’ve also observed similarities in binaries dating back to 2016, a clear indication that these threat actors have operated for nearly two years.