PowerRatankba

Aliases: QUICKRIDE.POWER

First seen
2019-05-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Last IoC activity
2026-07-22 04:03:51
Profile updated
2026-07-07 12:46:23

Targeted industries: government-and-public-sector

Targeted regions: country_code:cn country_code:us country_code:ru

Context

QUICKRIDE.POWER is a PowerShell variant of the QUICKRIDE backdoor. Its payloads are often saved to C:\windows\temp\

Reports & references

  • Mandiant — Rpt Apt38 (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • proofpoint.com — Pfpt Us Wp North Korea Bitten By Bitcoin Bug (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Power Ratankba (report)
  • riskiq.com — Lazarus Group Cryptocurrency (report)
  • Trend Micro — Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool Evolved Ratankba (report)
  • flashpoint-intel.com — Disclosure Chilean Redbanc Intrusion Lazarus Ties (report)

External references