HomeSecurityDark Caracal targets Latin America with Poco RAT

Dark Caracal targets Latin America with Poco RAT

A group known as Dark Caracal is allegedly linked to a campaign distributing the Poco RAT trojan, which targeted Spanish-speaking users in Latin America, in 2024.

Dark Caracal targets Latin America with Poco RAT

Russian cybersecurity firm Positive Technologies reported that the Poco RAT has a number of spying.

" It could upload files, take screenshots, execute commands and manipulate system processes ," researchers Denis Kazakov and Sergey Samokhin said

See also: Space Pirates targets Russian IT companies with LuckyStrike Agent malware

The Poco RAT was previously analyzed by Cofense, which reported that it was distributed via attacks phishing. The infection chains used financial themes as bait, which triggered a multi-step process for malware deployment.

Although the campaign was not attributed to any hacking group at the time, Positive Technologies said it identified overlaps with Dark Caracal, an advanced APT group known for operating malware such as CrossRAT and Bandook. The group has been active since at least 2012.

In 2021, hackers were linked to a cyber espionage campaign called Bandidos, which delivered an updated version of the Bandook malware against Spanish-speaking countries in South America.

The most recent attacks continue to target Spanish-speaking users, with phishing emails (with invoice-related topics) carrying malicious attachments, written in Spanish.

An analysis of Poco RAT artifacts by researchers shows that the attacks primarily target businesses in Venezuela, Chile, the Dominican Republic, Colombia, and Ecuador.

If victims open the attached files, they will be taken to a link that triggers the download of a .rev archive from legitimate file sharing services or cloud storage platforms, such as Google Drive and Dropbox.

See also: Phishing attacks distribute FatalRAT malware

“Files with the .rev extension are created via WinRAR,” the researchers explained. Attackers use them as hidden payload containers, helping the malware evade security detection.

The file contains a Delphi-based dropper responsible for launching the Poco RAT malware, which, in turn, establishes communication with a remote server and gives attackers full control over compromised hosts.

Some of the commands supported by Poco RAT are listed below:

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

T-01 – Send stolen system data to the command and control server (C2).
T-02 – Retrieve and transmit the active window title to the C2 server.
T-03 – Download and execute an executable file.
T-04 – Download a file to the compromised machine.
T-05 – Take a screenshot and send it to the C2 server.
T-06 – Execute a command in cmd.exe and send the result to the C2 server.

Dark Caracal Poco RAT

Protection against RAT malware

The first and most important way to protect against RAT malware is to install reliable security software. This software should include protection against viruses, spyware, malware, and other attacks, as well as the ability to detect and remove RATs.

Additionally, it is important to keep your operating system and all your applications up to date. These updates often include security that can protect your computer from the latest known trojans.

See also: Hackers exploit ClickFix to deploy NetSupport RAT

You should also be careful with emails and messages you receive. Many RAT malware (Poco RAT) are spread through phishing attacks, so avoid opening attachments or clicking links from unknown sources.

Using strong passwords and changing them regularly can also help protect against attacks . Using two-factor authentication can also add an extra layer of security.

Finally, information security training can be particularly useful. Understanding the ways in which RAT malware invades system and how to protect against them can help you stay safe.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS