⚔️ See how SentinelOne mitigates and rolls back RATDispenser malware loader. RATDispenser is a novel, JavaScript-based malware loader. It has been seen in conjunction with the delivery of multiple RAT families/campaigns and includes the distribution of Remcos, WSHRAT, Formbook, and many others. RATDispenser is typically distributed/delivered via a phishing email. The encoded JavaScript is decoded (at runtime) and written to %temp%. Any additional RAT payloads (in analyzed samples) are dropped into assigned directories in %appdata%/Roaming. Once a user is enticed into clicking/launching the javascript, the relevant installation script for the prescribed RAT will execute.
There is some variation across RATDispenser in that some analyzed variants will reach out to a C2 to download the necessary RAT payload. A majority of them, however, function as direct droppers.
#RATDispenser #ransomware #malware #cybersecurity #infosec #endpointprotection #endpointsecurity
SentinelOne PartnerOne - America's 2025
⛳️ Last week in Pebble Beach the America's best cybersecurity partners came together for our annual PartnerOne summit. Check out…
Just a Sec: Cybersecurity Unfiltered—Fast, Frank, and From the Front Lines
Welcome to the first-ever Just A Sec, a no-holds-barred, quick-fire monthly livestream. It’s cybersecurity like you’ve never heard it before—unfiltered,…
Observez comment notre plateforme de cybersécurité intelligente et autonome peut protéger votre entreprise contre les menaces actuelles et futures.