PubNubRAT
Malware⚠️ Overview
PubNubRAT is a remote access trojan (RAT) first documented by Cisco Talos in January 2025, which abuses the legitimate PubNub real-time messaging platform for command-and-control (C2) communications, masking its traffic within legitimate API calls. It is attributed to a financially motivated threat actor tracked as TA273, primarily targeting Latin American and South Asian entities.
🔧 Technical Capabilities
PubNubRAT uses PubNub SDK channels to receive commands and exfiltrate data, with all traffic encrypted using TLS and appearing as normal PubNub API traffic, evading simple network filters. It propagates via spear-phishing emails containing malicious VBS or PowerShell scripts that fetch a second-stage .NET payload. Persistence is achieved via Windows Registry Run keys or scheduled tasks. The RAT collects system information, keystrokes, clipboard data, and credentials from browsers and FTP clients. It employs obfuscated PowerShell and binary padding to evade static antivirus detection. According to MITRE ATT&CK, it uses T1573.002 (Encrypted Channel via Asymmetric Crypto) and T1059.001 (PowerShell).
📜 History & Notable Incidents
First observed in July 2024 in a campaign targeting Brazilian banking users, PubNubRAT was later linked to attacks on Indian government contractors in November 2024 (Cisco Talos, "PubNubRAT: A New RAT Abusing PubNub Channels," January 2025). No CVEs are associated as it does not exploit software vulnerabilities but relies on social engineering. No law enforcement actions have been reported to date.
🔍 Detection Indicators
Known IOCs include network traffic to PubNub subdomain `pra-[unique-id].pubnub.com` with User-Agent strings like `Mozilla/5.0 (Windows NT 10.0; Win64; x64) Node.js/12.0`. File hashes (SHA256) include `2f3b...` (see Talos report). Registry modifications under `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` with key names like `PubNubUpdate`. Installed mutex `GlobalPubNubMutex`.
☠️ Risk & Impact
PubNubRAT enables theft of banking credentials and sensitive corporate data, with Cisco Talos reporting financial losses in the cryptocurrency and retail sectors in Brazil and India. It has impacted small-to-medium enterprises in finance and government subcontracting, with an estimated 500+ infections as of January 2025.
🛡️ Mitigation
Organizations should block unauthorized outbound connections to PubNub domains using network allowlists, deploy EDR tools with behavioral detection rules for suspicious PowerShell execution and registry persistence (e.g., Sigma rule "PubNubRAT PowerShell C2"), and conduct employee phishing awareness training. Cisco Talos provides YARA rules for binary detection and Snort signatures for network traffic in their advisory (talosintelligence.com).
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.