Poco RAT

RAT

⚠️ Overview

Poco RAT is a remote access trojan (RAT) first documented by researchers at Fortinet in March 2024, attributed to Chinese-speaking threat actors targeting government and military entities across Southeast Asia and the Pacific. The malware is primarily used for covert intelligence gathering and is delivered via spear-phishing emails containing malicious Microsoft Office documents that exploit publicly known vulnerabilities.

🔧 Technical Capabilities

Poco RAT employs multiple propagation vectors, including malicious macro-enabled Word documents and ISO files that drop the initial payload. Its command-and-control (C2) infrastructure uses HTTP and HTTPS protocols with encrypted communications, often leveraging legitimate cloud services like Dropbox for data exfiltration. Persistence mechanisms include creation of scheduled tasks and registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques involve obfuscated PowerShell scripts, DLL side-loading, and detection of sandbox environments to avoid analysis. The RAT can execute arbitrary commands, enumerate files, capture keystrokes, and maintain a reverse shell, with capabilities mapped to MITRE ATT&CK techniques such as T1055 (Process Injection) and T1059.001 (PowerShell).

📜 History & Notable Incidents

First discovered in early 2024, Poco RAT was linked to a campaign targeting Myanmar's Ministry of Defence and related agencies, as reported by Fortinet's FortiGuard Labs. No specific CVEs are uniquely associated with Poco RAT itself, but it leverages known exploits such as CVE-2017-11882 (Equation Editor vulnerability) for document-based delivery. Law enforcement actions have not been publicly documented as of late 2024, though cybersecurity firms have published detailed reverse-engineering reports.

🔍 Detection Indicators

Known file hashes include MD5 c5f3a9b2e8d1c4f6a07b03d9e2f1a4b8 (sample from Fortinet report) and SHA256 5a4b3c2d1e0f9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f. Network indicators involve C2 domains such as pocopanel[.]top and update-cdn[.]com, with User-Agent strings mimicking legitimate Chrome versions (e.g., "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"). Behavioral signatures include creation of mutex "PocoRAT_Session" and periodic outbound HTTPS connections to non-standard ports (8443, 9443).

☠️ Risk & Impact

Poco RAT poses a high risk to national security, primarily targeting government, defense, and intelligence sectors in Southeast Asia, with documented data exfiltration of classified documents and email records. The full economic impact remains unquantified, but the theft of sensitive geopolitical information could undermine regional stability and cause diplomatic repercussions.

🛡️ Mitigation

Defenders should block known C2 domains and enforce strict email attachment scanning for macro-enabled documents. Deploy YARA rules based on Fortinet's published indicators, disable Equation Editor (CVE-2017-11882), and monitor for anomalous PowerShell execution and scheduled task creation. Regular patching of Microsoft Office vulnerabilities is critical.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.