Socket's Threat Research Team discovered a remote access trojan (RAT) distributed through three Packagist packages by threat actor nhattuanbl, disguised as Laravel utilities. The packages nhattuanbl/lara-helper and nhattuanbl/simple-queue contain an identical obfuscated PHP RAT payload in helper.php, while

8m read time From socket.dev
Post cover image
Table of contents
The Packages #The Payload #Activation #Self-Launch #C2 Communication #Reconnaissance #Command Set #The Dependency Chain Vector #Impact #Outlook and Recommendations #Indicators of Compromise (IOCs) #MITRE ATT&CK #
1 Comment

Sort: