PoetRAT
MITRE ATT&CK: S0428 View on attack.mitre.org
Aliases: PoetRAT
- First seen
- 2020-04-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 14:40:34
Targeted industries: energy-and-utilities government-and-public-sector
Targeted regions: country_code:az
Context
PoetRAT is a remote access trojan (RAT) that was first identified in April 2020. PoetRAT has been used in multiple campaigns against the private and public sectors in Azerbaijan, including ICS and SCADA systems in the energy sector. The STIBNITE activity group has been observed using the malware. PoetRAT derived its name from references in the code to poet William Shakespeare.
Detection coverage
- 681 Sigma rules
Malware & tools used
- Exfiltration Over C2 Channel (attack-pattern)
- File Transfer Protocols (attack-pattern)
- Command Obfuscation (attack-pattern)
- Windows Command Shell (attack-pattern)
- Exfiltration Over Alternative Protocol (attack-pattern)
- Malicious File (attack-pattern)
- Non-Standard Port (attack-pattern)
- Modify Registry (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Automated Collection (attack-pattern)
- Video Capture (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- System Checks (attack-pattern)
- Remote System Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- System Information Discovery (attack-pattern)
- Dynamic Data Exchange (attack-pattern)
- LSASS Memory (attack-pattern)
- Process Discovery (attack-pattern)
- Visual Basic (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Python (attack-pattern)
Reports & references
- Cisco Talos — Poetrat Update (report)
- Cisco Talos — Poetrat Covid 19 Lures (report)
- MITRE ATT&CK — S0428 (report)
- hub.dragos.com — Dragos 2020 Ics Cybersecurity Year In Review (report)