SYMBOLCOMMON_NAMEaka. SYNONYMS
win.unidentified_113 (Back to overview)

Unidentified 113 (RAT)


According to Phylum, this is a RAT with these characteristics:
* Registers as a scheduled task.
* Receives commands from a remote server using web sockets.
* Installs Chrome extensions to Secure Preferences.
* Configures AnyDesk, hides the screen, and disables shutting down Windows.
* Captures keyboard and mouse events.
* Collects information about files, browser extensions, and browser history.

References
2024-01-19PhylumPhylum Research Team
npm Package Found Delivering Sophisticated RAT
Unidentified 113 (RAT)

There is no Yara-Signature yet.