P8RAT

S0626

Malware.View on attack.mitre.org

About this malware

P8RAT is a fileless malware used by menuPass to download and execute payloads since at least 2020.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1001.001
Junk Data

P8RAT can send randomly-generated data as part of its C2 communication.

T1057
Process Discovery

P8RAT can check for specific processes associated with virtual environments.

T1105
Ingress Tool Transfer

P8RAT can download additional payloads to a target system.

T1497.001
System Checks

P8RAT can check the compromised host for processes associated with VMware or VirtualBox environments.

T1497.003
Time Based Checks

P8RAT has the ability to "sleep" for a specified time to evade detection.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Securelist APT10 March 2021 Open source
    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.