PoetRAT

S0428

Malware.View on attack.mitre.org

About this malware

PoetRAT is a remote access trojan (RAT) that was first identified in April 2020. PoetRAT has been used in multiple campaigns against the private and public sectors in Azerbaijan, including ICS and SCADA systems in the energy sector. The STIBNITE activity group has been observed using the malware. PoetRAT derived its name from references in the code to poet William Shakespeare.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1003.001
LSASS Memory

PoetRAT used voStro.exe, a compiled pypykatz (Python version of Mimikatz), to steal credentials.

T1018
Remote System Discovery

PoetRAT used Nmap for remote system discovery.

T1027
Obfuscated Files or Information

PoetRAT has used a custom encryption scheme for communication between scripts.

T1027.010
Command Obfuscation

PoetRAT has `pyminifier` to obfuscate scripts.

T1033
System Owner/User Discovery

PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2.

T1041
Exfiltration Over C2 Channel

PoetRAT has exfiltrated data over the C2 channel.

T1048
Exfiltration Over Alternative Protocol

PoetRAT has used a .NET tool named dog.exe to exiltrate information over an e-mail account.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

PoetRAT has used ftp for exfiltration.

T1056.001
Keylogging

PoetRAT has used a Python tool named klog.exe for keylogging.

T1057
Process Discovery

PoetRAT has the ability to list all running processes.

T1059.003
Windows Command Shell

PoetRAT has called cmd through a Word document macro.

T1059.005
Visual Basic

PoetRAT has used Word documents with VBScripts to execute malicious activities.

T1059.006
Python

PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools.

T1059.011
Lua

PoetRAT has executed a Lua script through a Lua interpreter for Windows.

T1070.004
File Deletion

PoetRAT has the ability to overwrite scripts and delete itself if a sandbox environment is detected.

View all 35 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. Dragos Threat Report 2020 Open source
    Dragos. (n.d.). ICS Cybersecurity Year in Review 2020. Retrieved February 25, 2021.
  2. Talos PoetRAT April 2020 Open source
    Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020.
  3. Talos PoetRAT October 2020 Open source
    Mercer, W. Rascagneres, P. Ventura, V. (2020, October 6). PoetRAT: Malware targeting public and private sector in Azerbaijan evolves . Retrieved April 9, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.