FatalRAT Malware Targets APAC Industries via Chinese Cloud Services
A highly sophisticated cyberespionage campaign is actively targeting various organizations across the Asia-Pacific (APAC) region, deploying the FatalRAT remote access trojan (RAT) to gain persistent access. The attackers are leveraging legitimate Chinese cloud services, including the myqcloud content delivery network (CDN) and Youdao Cloud Notes, to support their infrastructure and evade detection. Using a multi-stage payload delivery framework, they stealthily deploy malware while bypassing security defenses. FatalRAT grants attackers extensive control over infected systems, enabling keystroke logging, data theft, and remote command execution. While data exfiltration appears to be the primary goal, the malware’s capabilities suggest the potential for further disruptive or damaging actions.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox