Operation ElectroRAT: Attacker Creates Fake Companies and Uses New ElectroRAT to Drain Your Crypto Wallets
released on 2021-01-05 @ 04:05:54 PM
In December, Intezer discovered a wide-ranging operation targeting cryptocurrency users, estimated to have initiated in January 2020. This extensive operation is composed of a full-fledged marketing campaign, custom cryptocurrency-related applications and a new Remote Access Tool (RAT) written from scratch.
The campaign includes: Domain registrations, websites, trojanized applications, fake social media accounts and a new undetected RAT that we have named ElectroRAT. ElectroRAT is written in Golang and compiled to target multiple operating systems: Windows, Linux and MacOS.