SYMBOLCOMMON_NAMEaka. SYNONYMS
jar.epicsplit (Back to overview)

EpicSplit RAT


EpicSplit RAT is a multiplatform Java RAT that is capable of running shell commands, downloading, uploading, and executing files, manipulating the file system, establishing persistence, taking screenshots, and manipulating keyboard and mouse events. EpicSplit is typically obfuscated with the commercial Allatori Obfuscator software. One unique feature of the malware is that TCP messages sent by EpicSplit RAT to its C2 are terminated with the string "_packet_" as a packet delimiter.

References
2020-05-11Sudeep Singh
@online{singh:20200511:targeted:9ea90fd, author = {Sudeep Singh}, title = {{Targeted Attacks on Indian Government and Financial Institutions Using the JsOutProx RAT}}, date = {2020-05-11}, url = {https://www.zscaler.com/blogs/security-research/targeted-attacks-indian-government-and-financial-institutions-using-jsoutprox-rat}, language = {English}, urldate = {2021-06-01} } Targeted Attacks on Indian Government and Financial Institutions Using the JsOutProx RAT
EpicSplit RAT

There is no Yara-Signature yet.