Kasablanka is a threat actor referenced in the provided content as a group observed using AveMariaRAT (also known as WarZoneRAT) and as a group associated with the development of LodaRat4Android. ESET-linked reporting in the content states that the group used the Android 888 RAT and referred to it as LodaRAT, while BladeHawk referred to the same malware as Gaza007. The content also links Android 888 RAT to a campaign by the Kasablanka Group. Cisco Talos states there were no relevant overlaps between YoroTrooper and Kasablanka, and further notes that Kasablanka is not the sole operator of LodaRAT. No nation-state attribution is provided in the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as one of the threat groups observed using AveMariaRAT/WarZoneRAT.
Referenced as the developer (and sometimes operator) historically attributed with LodaRAT/Loda4Android; the report argues LodaRAT is used by multiple distinct operators and that YoroTrooper’s LodaRAT variants deviate from versions previously associated with Kasablanka.
Threat group linked in the report to use of Android 888 RAT in an organized campaign, referring to the malware as LodaRAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.