BalkanRAT
- First seen
- 2016-01-01 00:00:00
- Malware type
- rat, loader
- Family
- Malware family
- Profile updated
- 2026-07-07 14:48:03
Targeted industries: financial-services
Targeted regions: country_code:hr country_code:rs country_code:me country_code:ba
Context
The goal of BalkanRAT which is a more complex part of the malicious Balkan-toolset (cf. BalkanDoor) is to deploy and leverage legitimate commercial software for remote administration. The malware has several additional components to help load, install and conceal the existence of the remote desktop software. A single long-term campaign involving BalkanRAT has been active at least from January 2016 and targeted accouting departments of organizations in Croatia, Serbia, Montenegro, and Bosnia and Herzegovina (considered that the contents of the emails, included links and decoy PDFs all were involving taxes). It was legitimaly signed and installed by an exploit of the WinRAR ACE vulnerability (CVE-2018-20250).
Exploited vulnerabilities
- CVE-2018-20250 (vulnerability)
Reports & references
- ESET — Balkans Businesses Double Barreled Weapon (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Balkan Rat (report)