PowerRatankba
Aliases: QUICKRIDE.POWER
- First seen
- 2019-05-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:03:51
- Profile updated
- 2026-07-07 12:46:23
Targeted industries: government-and-public-sector
Targeted regions: country_code:cn country_code:us country_code:ru
Context
QUICKRIDE.POWER is a PowerShell variant of the QUICKRIDE backdoor. Its payloads are often saved to C:\windows\temp\
Reports & references
- Mandiant — Rpt Apt38 (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
- proofpoint.com — Pfpt Us Wp North Korea Bitten By Bitcoin Bug (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Power Ratankba (report)
- riskiq.com — Lazarus Group Cryptocurrency (report)
- Trend Micro — Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool Evolved Ratankba (report)
- flashpoint-intel.com — Disclosure Chilean Redbanc Intrusion Lazarus Ties (report)