BalkanRAT

First seen
2016-01-01 00:00:00
Malware type
rat, loader
Family
Malware family
Profile updated
2026-07-07 14:48:03

Targeted industries: financial-services

Targeted regions: country_code:hr country_code:rs country_code:me country_code:ba

Context

The goal of BalkanRAT which is a more complex part of the malicious Balkan-toolset (cf. BalkanDoor) is to deploy and leverage legitimate commercial software for remote administration. The malware has several additional components to help load, install and conceal the existence of the remote desktop software. A single long-term campaign involving BalkanRAT has been active at least from January 2016 and targeted accouting departments of organizations in Croatia, Serbia, Montenegro, and Bosnia and Herzegovina (considered that the contents of the emails, included links and decoy PDFs all were involving taxes). It was legitimaly signed and installed by an exploit of the WinRAR ACE vulnerability (CVE-2018-20250).

Exploited vulnerabilities

  • CVE-2018-20250 (vulnerability)

Reports & references

  • ESET — Balkans Businesses Double Barreled Weapon (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Balkan Rat (report)

External references