PoetRAT is a Windows remote access trojan used in targeted attacks against energy-sector environments involving industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems. It is delivered through spearphishing attachments containing malicious Microsoft Word documents and has used VBScript for malicious execution.
PoetRAT supports process enumeration, screenshot capture, ZIP compression of files, and collection of usernames, computer names, and unique victim identifiers for transmission to its command-and-control server. Its operations have used Nmap for remote-system discovery, a compiled pypykatz implementation for credential theft, and a Python-based tool for stealing browser credentials. It establishes persistence through Windows Registry entries and modifies Registry settings to alter execution behavior. Data has been exfiltrated through its command-and-control channel and through an auxiliary .NET tool using an email account. Anti-analysis behavior includes treating disks smaller than 62 GB as indicators of a sandbox, while LZMA and Base64 decoding are used to unpack obfuscated scripts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
STIBNITE sent victims spear-phishing emails about such events as a first lure and attempt at installing a new version of PoetRAT written in .NET.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
77 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan that sends username, computer name, and UUID to C2.
Uses Word documents with VBScripts to execute malicious activity.
Uses a compiled pypykatz executable named voStro.exe for credential theft.
Uses Nmap to discover remote systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.