MagicRAT Possibly Linked to Lazarus Group APT

MagicRAT is a newly discovered remote access trojan malware. Researchers have discovered signs and markers that link the new RAT to the North Korean advanced persistent threat actor known as Lazarus Group.

MagicRAT is focused primarily on stealthy infiltration and maintaining a low profile on the compromised system. While the malware can perform pretty significant malicious tasks, its feature set is relatively limited, compared to other remote access malicious tools.

MagicRAT can manipulate files on the infected system, including moving, deleting or renaming them. The real purpose and focus of MagicRAT seem to be dropping additional malware, not so much scraping and exfiltrating information.

Researchers have observed the malware acting as a downloader and dropper for additional malicious payloads, including the TigerRAT - another piece of malware associated with the Lazarus Group APT.

The Lazarus Group is known for supporting its tools, so future updates to MagicRAT may bring more advanced functionality to the malware.

September 12, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.