Cardinal

First seen
2017-01-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 14:32:56

Targeted industries: financial-services technology-and-telecommunications

Targeted regions: country_code:il

Context

Cardinal is a remote access trojan (RAT) discovered by Palo Alto Networks in 2017 and has been active for over two years. It is delivered via a downloader, known as Carp, and uses malicious macros in Microsoft Excel documents to compile embedded C# programming language source code into an executable that runs and deploys the Cardinal RAT. The malicious Excel files use different tactics to get the victims to execute it.

Reports & references

  • Palo Alto Unit 42 — Cardinal Rat Sins Again Targets Israeli Fin Tech Firms (report)
  • researchcenter.paloaltonetworks.com — Unit42 Cardinal Rat Active Two Years (report)
  • scmagazine.com — 651927 (report)
  • cyber.nj.gov — Cardinal (report)

External references