Poet RAT
- First seen
- 2019-01-01 00:00:00
- Malware type
- rat
- Profile updated
- 2026-07-07 13:06:32
Targeted industries: government-and-public-sector
Targeted regions: country_code:tr
Context
Cisco Talos has discovered a Python-based RAT they call Poet RAT. It is dropped from a Word document and delivered including a Python interpreter and required libraries. The name originates from references to Shakespeare. Exfiltration happens through FTP.
Reports & references
- Cisco Talos — Yorotrooper Espionage Campaign Cis Turkey Europe (report)
- ics-cert.kaspersky.com — Kaspersky H1 2020 Ics Report En (report)
- Cisco Talos — 2020 Year In Malware (report)
- Kaspersky — 99204 (report)
- malpedia.caad.fkie.fraunhofer.de — Py.Poet Rat (report)
- dragos.com — New Ics Threat Activity Group Stibnite (report)
- cyborgsecurity.com — Python Malware On The Rise (report)
- Cisco Talos — Poetrat Update (report)
- ptsecurity.com — Antisandbox Techniques (report)
- Cisco Talos — Poetrat Covid 19 Lures (report)