DinodasRAT

General News

Summary

In October 2023, investigators disclosed that a governmental body in Guyana was under siege as part of a cyber espionage initiative termed Operation Jacana, focusing on deploying the Windows iteration of this threatening implant. In late March 2024, researchers outlined a cluster of threat activities known as Earth Krahang, which has apparently transitioned to employing DinodasRAT since 2023 in its assaults, targeting numerous government entities across the globe. DinodasRAT comes equipped with a variety of capabilities, including file operations, altering Command-and-Control (C2) addresses, identifying and terminating active processes, executing shell commands, fetching updated versions of the backdoor, and even self-removal. Their decision to support this operating system goes beyond a mere adaptation of a Windows Remote Access Trojan (RAT) with conditional compilation directives (#ifdef). This strategy likely capitalizes on the comparatively lower level of security measures typically deployed on Linux systems, enabling attackers to deepen their foothold and operate covertly for extended periods.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M