Escanor RAT Creeps on the Dark Web

A research team with security company Resecurity discovered a new malicious tool being distributed on the dark web. The new malware is a remote admin tool that was dubbed Escanor.

The earliest sighting of Escanor dates back to the first month of 2022. The malware is distributed through a Telegram channel as well, where it has gained significant traction, approaching 30 thousand subscribers.

The malicious payload of Escanor is distributed using doctored Office and PDF files. The malware also has a mobile version that works by intercepting single-use passwords sent to banking application users. The mobile version of the malware is known under the alias Esca RAT.

In addition to being used for banking fraud and potential theft, Esca RAT can monitor the GPS location of the infected device, log keystrokes from it and exfiltrate files.

The RAT is associated with a threat actor known by the alias AridViper, which targeted entities located in Israel in the past.

The new victims infected with the Escanor have been located all over the globe, including the Americas, the United Arab Emirates, Bahrain, Mexico and Singapore.

August 23, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.