Woody RAT

The Woody RAT (Remote Access Trojan) is a sophisticated threat, capable of performing numero, intrusive and hurtful actions on infected devices. The threat has been observed to be deployed as part of attack campaigns targeting Russian entities, such as the United Aircraft Corporation (AOK). Once executed, Woody RAT can be used in espionage activities or used as a delivery system for more specialized malware threats. 

To be more precise, the Woody RAT can extract various system data including the OS version and architecture, computer name, user accounts and their associated privileges, the currently active processes, any present anti-malware solutions and more. The attackers also can use the threat to collect private information from their targets. The Woody RAT also can obtain file names, file types, their creation, access, and modification times, permissions and more. If instructed, the threat can take screenshots of the system. 

Depending on the specific goals of the threat actors, the Woody RAT can exfiltrate chosen files - upload them to a remote server controlled by the hackers, or fetch and execute additional payloads. This functionality allows the cybercriminals to deliver threats, such as spyware, ransomware and more to the victim's device. 

Trending

Most Viewed

Loading...