Uptime Hamster: 11d 13h 15mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza TeamXRat

TeamXRat

0 incidentes 0 paises 0 sectores apt BR Ultimo: -
Aliases: CorporacaoXRat, CorporationXRat
Ver en IntelTracker → APTTrail →
TeamXRat is a Brazilian cyber espionage group that first emerged around 2013, with its earliest malware samples observed in that year. The group's primary motivation is the extraction of sensitive information, primarily targeting financial institutions, government agencies, and telecommunication organizations within Latin America, particularly Brazil. TeamXRat is distinguished by its use of custom Remote Access Trojans (RATs), which are often written predominantly in Portuguese and sometimes leverage legitimate software like TeamViewer for command and control. The group has demonstrated an evolution in its operational methods, including an increase in the sophistication of its spear-phishing lures and the incorporation of social engineering techniques over time. TeamXRat also operates under the names Win.Xpan, CorporacaoXRat, and CorporationXRat.

Aliases del actor

CorporacaoXRatCorporationXRat
Tecnicas MITRE
T1137, T1083, T1085, T1555, T1547, T1218 - Signed Binary Proxy Execution
CVEs relacionadas
CVE-2023-38831, CVE-2023-36884, CVE-2022-47966, CVE-2022-42475, CVE-2021-33764, CVE-2020-1472
Tipo
apt
Pais origen
BR
Motivacion
-
Impacto
29
Actualizado
Wed, 01 Ju

Sectores objetivo (SOCRadar)

Public AdministrationBanking