Talos Takes

Update on LodaRAT and its many variants

December 02, 2022 Cisco Talos Episode 121
Talos Takes
Update on LodaRAT and its many variants
Show Notes

LodaRAT is an AutoIT based RAT that has been distributed for the last several years. Initially tied to the Kasablanka group its distribution has grown over the years. In this episode we'll be talking with the researcher, Chris Neal, to discuss LodaRAT, the campaigns we've been observing along with some key tidbits about how AutoIT is abused by adversaries. Including some fun with decompiling and recompling.