Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

SuperBlocks CEO: How to study AI system prompts and find unicorn ideas

“Bitcoin Family” changed its security after the recent cryptocurrency

AB will be released at Binance -Tech Startups

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Dark Caracal uses Poco Rat to target Spanish-speaking companies in Latin America
Identity

Dark Caracal uses Poco Rat to target Spanish-speaking companies in Latin America

userBy userMarch 5, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 5, 2025Ravi LakshmananCyber ​​Spy/Malware

The threat actor, known as Dark Caracal, was attributed to a campaign in 2024 that deployed a remote access trojan called Poco Rat in an attack targeting Spanish-speaking targets in Latin America.

The findings are from the Russian cybersecurity company’s positive technology, and the malware is described as loaded with a “spionage set of features.”

“You can upload files, capture screenshots, execute commands, and operate system processes,” Denis Kazakov and Sergey Samokhin said in a technical report published last week.

Poco Rat was previously recorded by Cofense in July 2024, detailing phishing attacks aimed at the mining, manufacturing, hospitality and utility sectors. Infection chains are characterized by the use of financial-themed lures that trigger a multi-step process for deploying malware.

Cybersecurity

The campaign wasn’t attributed to the threats of the time, but it said Positive Technology has identified a duplicate product with Dark Caracal, an advanced permanent threat (APT) known for running malware families such as Crossrat and Bandook. It has been in operation since at least 2012.

In 2021, the Cybermercists group was tied up with a bandid called the Cyberspy Campaign, which provided an updated version of Bandok malware for Spanish-speaking countries in South America.

The latest set of attacks continues to focus on Spanish-speaking users, leveraging phishing emails on invoice-related topics that are responsible for malicious attachments written in Spanish as the starting point. Analysis of Pokorat’s artifacts shows that invasions primarily target companies in Venezuela, Chile, the Dominican Republic, Colombia and Ecuador.

The attached decoy document impersonates verticals for a wide range of industries, including banking, manufacturing, medical, pharmaceuticals, logistics, and more, in an attempt to believe the scheme a little more.

When opened, the file redirects the victim to a link that triggers downloading of the .rev archive from legitimate file sharing services, such as Google Drive or Dropbox, or from cloud storage platforms.

“Files with the .rev extension were generated using Winrar and were originally designed to rebuild missing or corrupt volumes in multipart archives,” the researchers explained. “Threat actors can reuse them as stealth payload vessels, helping malware avoid security detection.”

In the archive, there is a Delphi-based Dropper responsible for launching Poco Rat. This allows you to establish contact with a remote server and have full control over the host compromised by the attacker. Malware retrieves names from using the POCO library in the C++ codebase.

Cybersecurity

Some of the supported commands by Poco Rat are listed below –

T-01 – Send collected system data to the Command and Control (C2) server T-02 – Get and send active window title to C2 server T-03 – Download and run executable file T-04.

“Pokorats do not have built-in persistence mechanisms,” the researchers said. “After the initial reconnaissance is complete, the server may issue commands to establish tenacity. Alternatively, an attacker can deploy the main payload using Poco Rat as a stepping stone.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleUK public EV charge point infrastructure boom exceeds 75,000
Next Article $ RNT: Real estate tokenization token
user
  • Website

Related Posts

The new Atomic Macos Stealer campaign targets Apple users by exploiting Clickfix

June 6, 2025

Empower users and protect against Genai data loss

June 6, 2025

Microsoft will help CBI to dismantle the Indian call centre behind Japan’s technical assistance scam

June 6, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

SuperBlocks CEO: How to study AI system prompts and find unicorn ideas

“Bitcoin Family” changed its security after the recent cryptocurrency

AB will be released at Binance -Tech Startups

After data is wiped out, Kiranapro co-founders cannot rule out external hacks

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

AB will be released at Binance -Tech Startups

Top 10 Startups and Tech Funding News for the Weekly Ends June 6, 2025

Order openai to keep all chatgpt logs including deleted temporary chats, API requests

Omada Health is now available: Virtual Care Startup joins IPO Wave, paying $150 million, $1.1 billion valuation of NASDAQ debut

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.