RATANKBA

MITRE ATT&CK: S0241 View on attack.mitre.org

Aliases: QUICKRIDE, RATANKBA

First seen
2017-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:46:27

Targeted industries: financial-services technology-and-telecommunications professional-services education-and-nonprofits

Targeted regions: country_code:pl country_code:mx country_code:uy country_code:gb country_code:cl

Context

RATANKBA is a remote controller tool used by Lazarus Group. RATANKBA has been used in attacks targeting financial institutions in Poland, Mexico, Uruguay, the United Kingdom, and Chile. It was also seen used against organizations related to telecommunications, management consulting, information technology, insurance, aviation, and education. RATANKBA has a graphical user interface to allow the attacker to issue jobs to perform on the infected machines.

Detection coverage

  • 1 YARA rules
  • 487 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Local Account (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • PowerShell (attack-pattern)
  • System Information Discovery (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Ratankba_Auto (yara-rule)

Reports & references

  • Mandiant — Rpt Apt38 (report)
  • Broadcom/Symantec — Attackers Target Dozens Global Banks New Malware (report)
  • secureworks.com — Nickel Gladstone (report)
  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • proofpoint.com — Pfpt Us Wp North Korea Bitten By Bitcoin Bug (report)
  • raw.githubusercontent.com — Group Ib Lazarus (report)
  • Trend Micro — Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool Evolved Ratankba (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ratankba (report)
  • baesystemsai.blogspot.de — Cyber Heist Attribution (report)
  • Broadcom/Symantec — Attackers Target Dozens Of Global B (report)
  • Broadcom/Symantec — Attackers Target Dozens Global Banks New Malware 0 (report)
  • baesystemsai.blogspot.com — Lazarus Watering Hole Attacks (report)
  • bleepingcomputer.com — Polish Banks Infected With Malware Hosted On Their Own Governments Site (report)
  • twitter.com — 828915536268492800 (report)
  • MITRE ATT&CK — S0241 (report)
  • Trend Micro — Ratankba Watering Holes Against Enterprises (report)

External references