3PARA RAT is a remote access trojan used for command-and-control over HTTP. It supports encrypted C2 communications, using DES in CBC mode with a key derived from an MD5 hash, and includes a fallback XOR-based decoding routine if DES decoding fails. The malware includes host interaction capabilities such as listing the current working directory, retrieving file metadata, and modifying file attributes including creation and modification timestamps, indicating both file-system reconnaissance and defense-evasion functionality through timestomping. The documented behavior is consistent with a Windows-focused intrusion tool used for post-compromise remote access and operator tasking.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan with functionality to modify file creation and modification timestamps.
Remote access trojan whose HTTP C2 commands are encrypted with DES-CBC, with XOR fallback if DES decoding fails.
Remote access trojan that encrypts HTTP C2 commands using DES-CBC (fallback XOR if DES decode fails).
Remote access trojan that uses HTTP for command-and-control (C2).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.