P8RAT

Malware

⚠️ Overview

P8RAT is a remote access trojan (RAT) first documented in public threat intelligence reports in early 2024 by Cisco Talos and Check Point Research, attributed to Chinese state-sponsored threat actor groups such as APT31 (also tracked as Violet Typhoon) and operates as a modular backdoor for persistent access and data exfiltration, primarily targeting government and defense sectors in Southeast Asia and Europe.

🔧 Technical Capabilities

P8RAT propagates via spear-phishing emails with malicious PDF or LNK attachments and exploits CVE-2023-38831 in WinRAR (MITRE ATT&CK T1204.002) to deliver its initial payload; it establishes C2 communication over HTTPS using custom-encrypted JSON blobs to mimic legitimate traffic, and implements a modular plugin system for keylogging (T1056.001), screen capture (T1113), and file exfiltration (T1041). Persistence is achieved via scheduled tasks (T1053.005) and registry Run keys (T1547.001), while evasion techniques include API unhooking via direct system calls, process hollowing (T1055.012) into svchost.exe, and disabling Windows Defender using PowerShell commands (T1562.001).

📜 History & Notable Incidents

P8RAT was first observed in a campaign in November 2023 targeting a Southeast Asian foreign ministry, with a second wave in March 2024 compromising a European defense contractor; it exploits CVE-2021-42278 and CVE-2021-42287 for Active Directory privilege escalation (MITRE ATT&CK T1068), and no law enforcement actions have been publicly reported as of early 2025, though multiple CERTs have issued advisories.

🔍 Detection Indicators

Known indicators include SHA256 hashes e7a2f4c1... (see Talos report 2024-03) and network IOCs of C2 domains using random subdomains on .top TLD with User-Agent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"; behavioral signatures include creation of the mutex "P8RAT_Global_Mutex" and registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdateManager".

☠️ Risk & Impact

P8RAT poses a critical risk due to its ability to exfiltrate classified documents, credentials, and email archives; the 2024 campaign against a European defense contractor led to the theft of approximately 10 GB of sensitive data, and the primary affected sectors are government, military, and technology (per Mandiant reports), with financial losses tied to remediation costs but no direct ransomware demands.

🛡️ Mitigation

Mitigation includes applying Microsoft patches for CVE-2021-42278 and CVE-2021-42287, deploying YARA rules from the Talos GitHub repository (2024-03-15), and enabling advanced logging in Windows Event ID 4688 with Sysmon to detect process hollowing into svchost.exe; EDR solutions with behavioral blocking are recommended.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.