logo

PyStoreRAT_ThreatAnalysis.pdf

ID: ea47f124-9023-4893-a2c8-46d21753bf49

STIX ID: report--ea47f124-9023-4893-a2c8-46d21753bf49

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2025-12-09

Last Modified Date: 2025-12-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**PyStoreRAT — GitHub-delivered HTA/JS RAT:** Morphisec Threat Labs analyzed PyStoreRAT, a modular, fileless JavaScript RAT executed via mshta/HTA and delivered through small Python/JS loader stubs embedded in seemingly legitimate GitHub repos; the implant supports multiple payload types (EXE/DLL/PS/MSI/Python/HTA), implements persistence via scheduled tasks, USB spreading, custom C2 session/token logic, manual deserialization to evade detection, and explicit evasion targeting CrowdStrike Falcon, and was observed deploying the Rhadamanthys stealer — the report provides technical details and IOCs (malicious repos, domains, download URLs, and hashes).