Summary: 2025/04/25 09:16
First reported date: 2011/08/12
Inquiry period : 2025/04/18 09:16 ~ 2025/04/25 09:16 (7 days), 2 search results
전 기간대비 신규 트렌드를 보이고 있습니다.
악성코드 유형 RMS rurat NetWireRC RATel Ransomware CACTUS 도 새롭게 확인됩니다.
공격기술 Exploit Campaign 도 새롭게 확인됩니다.
기관 및 기업 Google Mandiant Cisco Kaspersky Russia Microsoft UN 도 새롭게 확인됩니다.
기타 Cobalt Strike Email Windows Update Advertising 등 신규 키워드도 확인됩니다.
CyberInt states that Remote Manipulator System (RMS) is a legitimate tool developed by Russian organization TektonIT and has been observed in campaigns conducted by TA505 as well as numerous smaller campaigns likely attributable to other, disparate, threat actors. In addition to the availability of commercial licenses, the tool is free for non-commercial use and supports the remote administration of both Microsoft Windows and Android devices. Ref.
* 최근 뉴스기사 Top3:
ㆍ 2025/04/23 Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs
참고로 동일한 그룹의 악성코드 타입은 Remcos njRAT QuasarRAT 등 112개 종이 확인됩니다.
Trend graph by period
Related keyword cloud
Top 100# | Trend | Count | Comparison |
---|---|---|---|
1 | RMS | 2 | ▲ new |
2 | Cobalt Strike | 1 | ▲ new |
3 | 1 | ▲ new | |
4 | Windows | 1 | ▲ new |
5 | Update | 1 | ▲ new |
6 | Exploit | 1 | ▲ new |
7 | Advertising | 1 | ▲ new |
8 | 1 | ▲ new | |
9 | Mandiant | 1 | ▲ new |
10 | Backdo | 1 | ▲ new |
11 | Cisco | 1 | ▲ new |
12 | rurat | 1 | ▲ new |
13 | es | 1 | ▲ new |
14 | Además | 1 | ▲ new |
15 | instalar | 1 | ▲ new |
16 | persistencia | 1 | ▲ new |
17 | desactivar | 1 | ▲ new |
18 | NetWireRC | 1 | ▲ new |
19 | RATel | 1 | ▲ new |
20 | MFA | 1 | ▲ new |
21 | Watchdog | 1 | ▲ new |
22 | c&c | 1 | ▲ new |
23 | Vulnerability | 1 | ▲ new |
24 | Malware | 1 | ▲ new |
25 | Kaspersky | 1 | ▲ new |
26 | Forensics | 1 | ▲ new |
27 | Russia | 1 | ▲ new |
28 | Campaign | 1 | ▲ new |
29 | IoC | 1 | ▲ new |
30 | Victim | 1 | ▲ new |
31 | Ransomware | 1 | ▲ new |
32 | powershell | 1 | ▲ new |
33 | Microsoft | 1 | ▲ new |
34 | CACTUS | 1 | ▲ new |
35 | PDB | 1 | ▲ new |
36 | Zero Trust | 1 | ▲ new |
37 | schtasks | 1 | ▲ new |
38 | UN | 1 | ▲ new |
Special keyword group
Top 5
Malware Type
This is the type of malware that is becoming an issue.
Keyword | Average | Label |
---|---|---|
RMS |
|
2 (28.6%) |
rurat |
|
1 (14.3%) |
NetWireRC |
|
1 (14.3%) |
RATel |
|
1 (14.3%) |
Ransomware |
|
1 (14.3%) |

Attacker & Actors
The status of the attacker or attack group being issued.
Keyword | Average | Label |
---|
Malware Family
Top 5
A malware family is a group of applications with similar attack techniques.
In this trend, it is classified into Ransomware, Stealer, RAT or Backdoor, Loader, Botnet, Cryptocurrency Miner.
Threat info
Last 5SNS
(Total : 1)News
(Total : 1)Cobalt Strike Zero Trust Email Mandiant Google Advertising Exploit Update Windows RMS RATel Cisco MFA Ransomware schtasks PDB Watchdog CACTUS Microsoft powershell Attacker Victim c&c IoC Campaign Russia Forensics Kaspersky Malware Vulnerability
No | Title | Date |
---|---|---|
1 | Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs - Malware.News | 2025.04.23 |
Additional information
No | Title | Date |
---|---|---|
1 | VulnCheck spotted 159 actively exploited vulnerabilities in first few months of 2025 - CyberScoop | 2025.04.25 |
2 | FBI asks public for tips about Salt Typhoon telecom hacks - Malware.News | 2025.04.25 |
3 | Alphabet Sales Beat Estimates on Google Search Advertising - Bloomberg Technology | 2025.04.25 |
4 | T-Mobile Shares Slump After New Wireless Customers Fall Short - Bloomberg Technology | 2025.04.25 |
5 | Tesla’s Europe Sales Fall, IBM and ServiceNow Beat | Bloomberg Technology - Bloomberg Technology | 2025.04.25 |
View only the last 5 |
No | Title | Date |
---|---|---|
1 | Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs - Malware.News | 2025.04.23 |
2 | Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs - Malware.News | 2025.04.23 |
3 | Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs - Malware.News | 2025.04.23 |
4 | Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs - Malware.News | 2025.04.23 |
5 | Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs - Malware.News | 2025.04.23 |
View only the last 5 |
No | URL | CC | ASN Co | Reporter | Date |
---|---|---|---|---|---|
1 | https://floatnightlife.com/rms.msi?sn=65 rms | GB ![]() | DiViNetworks LTD. | abuse_ch | 2025.03.08 |