MSIL.Backdoor.SocketPlayer.A
released on 2018-06-05 @ 06:55:30 PM
The RAT is written in .NET and the source-code can therefore be inspected easily. The RAT uses socket.io for communication which is not that typical for malware hence it captured my attention. It appears that the border security force of India website has been used to spread malware including SocketPlayer downloader