A new rat in the valley: SAFERAT
Key takeaways
- Discovery of a new malware “SafeRat” attributed to the Silver Fox group
- Description of SafeRat’s operation
- Discovery of a new “UUIDLoader” loader
- Establishing a link with ValleyRat and Silver Fox
- Script for extracting loader payloads
- IOCs, detection guide, and sample list
This article details a new malicious code, SafeRat, which we attribute to the APT group Silver Fox.
First, we will describe this new code, its operation, capabilities and specificities.. We will look at certain interesting functionalities such as the silent deployment of an RMM (Remote Monitoring and Management) solution. We will also cover the elements identified in the wild, and notably the presumed victimology.
Read more...