Poet RAT

First seen
2019-01-01 00:00:00
Malware type
rat
Profile updated
2026-07-07 13:06:32

Targeted industries: government-and-public-sector

Targeted regions: country_code:tr

Context

Cisco Talos has discovered a Python-based RAT they call Poet RAT. It is dropped from a Word document and delivered including a Python interpreter and required libraries. The name originates from references to Shakespeare. Exfiltration happens through FTP.

Reports & references

  • Cisco Talos — Yorotrooper Espionage Campaign Cis Turkey Europe (report)
  • ics-cert.kaspersky.com — Kaspersky H1 2020 Ics Report En (report)
  • Cisco Talos — 2020 Year In Malware (report)
  • Kaspersky — 99204 (report)
  • malpedia.caad.fkie.fraunhofer.de — Py.Poet Rat (report)
  • dragos.com — New Ics Threat Activity Group Stibnite (report)
  • cyborgsecurity.com — Python Malware On The Rise (report)
  • Cisco Talos — Poetrat Update (report)
  • ptsecurity.com — Antisandbox Techniques (report)
  • Cisco Talos — Poetrat Covid 19 Lures (report)

External references