April 21, 2020, 12:00 PM E.T.

How to Combat the Kwampirs RAT Using Yara

The threat landscape is complex and attackers are evolving quickly. The Kwampirs RAT (remote access trojan) is a case in point. Developed by the Orangeworm attack group, this RAT has targeted the software supply chain, as well as industries including healthcare, energy, etc.
We'll show you easy ways to search for file-based threats, exposing our human readable indicators and explainable threat intelligence, and demonstrating how to take action by hunting for variants of the Kwampirs RAT using YARA.