PowerRatankba.A is a remote access trojan associated with the CryptoMimic intrusion set, a financially motivated threat cluster active since at least 2018 that has heavily targeted banks, financial organizations, and especially cryptocurrency-related companies. It is referenced as sharing notable similarities with the Cabbage RAT malware family used in CryptoMimic operations, indicating comparable command-and-control and post-compromise tradecraft.
CryptoMimic intrusions commonly begin with spearphishing emails or LinkedIn lures that direct victims to cloud-hosted archives containing a decoy document and a malicious shortcut file. Subsequent stages in these operations have used script-based downloaders and RAT components to establish persistence, profile victims, execute attacker-supplied code, and selectively continue or terminate the intrusion based on victim value. Within this ecosystem, PowerRatankba.A is characterized as a RAT comparable to Cabbage RAT variants that support interactive remote command execution and staged follow-on activity.
The broader malware cluster linked to these operations demonstrates capabilities including reconnaissance, persistence, command execution, file transfer, download-and-execute behavior, credential and browser data theft, process injection, and defense evasion through anti-analysis checks and cleanup actions. CryptoMimic operators have also been observed deleting logs and removing artifacts after operations, and some later-stage tooling has included credential theft from browser stores and abuse of Windows security mechanisms. Reporting has noted multiple similarities between CryptoMimic tooling and Lazarus-linked activity, but any direct attribution remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a RAT with similarities to Cabbage RAT in command structure and URL pattern.
A malware family mentioned as similar to Cabbage RAT-B in terms of commands and URL patterns.
Referenced as a RAT with similarities to Cabbage RAT in command structure and URL pattern.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.