Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Dark Caracal uses Poco Rat to orientation on Hispanic Enterprises in Latin America
Global Security

Dark Caracal uses Poco Rat to orientation on Hispanic Enterprises in Latin America

AdminBy AdminMarch 5, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


05 March 2025Red LakshmananCyber ​​-bue / malicious software

Actor threats known as Dark Caracal was associated with a company that launched a remote access titled by Poco Rat when attacking Hispanic purposes in Latin America in 2024.

The resulting data come from the Russian cybersecurity company of positive technologies that described malicious software loaded with a “full set of espionage”.

“It can download files, record screenshots, execute teams and manipulate systems,” – researchers Denis Kazakov and Sergei Samokhin – Note In a technical report published last week.

Poco rat was Previously documented Coffense in July 2024, which details the phishing attacks aimed at mining, production, hospitality and utilities. The infection networks are characterized by the use of bait with the topic of financing, which cause a multi -stage process to deploy malware.

Cybersecurity

While the company at the time did not explain the threat Dark Caracal. Crossrat and Bandook. It has been operating at least since 2012.

In 2021, the cyber -naval group was challenged To the cyber-spying company, called Bandidos, which delivered the updated version of the Bandook malicious software against Hispanic countries of South America.

The latest set of attacks continues to focus on Hispanic users, using phishing-leaf-related accounts that carry malicious investments written in Spanish as a starting point. The analysis of the Poco rat artifacts shows that the invasion is mainly focused on enterprises in Venezuela, Chile, the Dominican Republic, Colombia and Ecuador.

The attached documents representing themselves represent themselves a wide range of branch verticals, including banking, production, health care, pharmaceuticals and logistics, in an attempt to borrow a slightly more plausibility scheme.

When opening, the files redirect the victims to the link that launches the archive .Rev from legitimate file distribution services or cloud platforms such as Google Drive and Dropbox.

“Files with .Rev expansion generated by Winrar and were originally designed to reconstruct the missing or damaged volumes in multi-storey archives,” the researchers explained. “The actors threaten them as hidden containers of useful load, helping malicious software to evade security.”

The archive contains a dropper based on Delphi, which is responsible for launching a POCO RAT, which in turn establishes contact with a remote server and gives the attackers full control over the compromised hosts. Malicious software gets its name from using POCO libraries in its C ++ database.

Cybersecurity

Some of the supported Poco Rat commands below –

  • T-01-RECEIVED SYSTEM SYSTEM SYSTEMS TO THE SEVER Teams and Control (C2)
  • T -02 – Getting and transfer an active window header to C2 server
  • T -03 – Download and run the executed file
  • T -04 – Download the file on a compromised machine
  • T -05 – Fix the screenshot and send it to the C2 server
  • T -06 – Complete the command in cmd.exe and send the exit to the C2 server

“The Poco rat does not go with the built-in persistence,” the researchers said. “Once the initial exploration is complete, the server probably issues a perseverance team, or attackers can use Poco Rat as a step to deploy the main useful load.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.