PoetRAT is a custom remote access malware family associated with the STIBNITE threat activity group and used in intrusion operations targeting organizations in Azerbaijan, including government and wind-generation entities. It has been employed primarily for information gathering and post-compromise operations in environments of industrial interest, with observed activity focused on IT networks and assessed as potentially supporting later access into ICS environments.
PoetRAT provides typical RAT functionality for host surveillance and operator tasking. Documented capabilities include listing files and running processes, collecting host and user information, taking screenshots, transferring files, executing commands, hiding and unhiding files, and exfiltrating data over its command-and-control channel. It has also been linked to browser credential theft through an auxiliary Python-based component and to alternate-protocol exfiltration through a .NET utility that sent information via email. Persistence has been established through Windows Registry autorun modifications, and the malware has used registry changes to alter runtime behavior. Obfuscated scripts associated with PoetRAT have used Base64 and LZMA decoding routines.
Observed delivery relied on spearphishing with malicious Microsoft Word documents, including documents containing VBScript-based execution chains. STIBNITE also used spoofed credential-harvesting websites in broader operations, but PoetRAT itself is specifically documented as being delivered through spearphishing attachments. The malware is a Windows-focused implant and has been described as part of a broader toolset used for credential collection, reconnaissance, and post-exploitation in campaigns aligned with strategic targeting of Azerbaijani industrial and government sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
STIBNITE sent victims spear-phishing emails about such events as a first lure and attempt at installing a new version of PoetRAT written in .NET.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
OT operators should look for PoetRAT activity in IT and OT environments through execution of Python and Lua.
The content notes use of macros in Word/Office documents and VB scripts, including examples such as APT28, Dark Caracal, menuPass, TrickBot, OceanSalt, OilRig, Nomadic Octopus, and SQLRat executing VB scripts on hosts.
OT operators should look for PoetRAT activity in IT and OT environments through execution of Python and Lua.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage... has used tools to dump passwords from browsers... can steal saved usernames and passwords in Chrome... dumped the login data database from \AppData\Local\Google\Chrome\User Data\Default\Login Data
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
Confucius has used a file stealer to steal documents and images... Patchwork developed a file stealer to search C:\ and collect files with certain extensions... Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
STIBNITE is known to use Dynamic Domain Name System (DDNS) and common ports for C2 traffic.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
71 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan that sends username, computer name, and UUID to C2.
Uses Word documents with VBScripts to execute malicious activity.
A Python-based remote access trojan that provides persistent access and control, often delivered via malicious documents.
Remote access trojan observed using a tool to steal browser credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.