Ping32 RMM and ValleyRAT
Brief
Fareed Radzi recently blogged about a malware campaign observed earlier in June by Kaspersky’s GReAT team. The malware campaign embedded malicious code in VBScripts, which were distributed through WhatsApp DMs. The VBScript then dropped the legitimate Remote Monitoring and Management (RMM) tool ManageEngine Endpoint Central.
Fareed included the IOCs for the following Endpoint Central server IP addresses:
- 202.61.160.208
- 202.61.160.202
- 202.61.160.201
- 202.61.160.160
- 202.61.160.137
- 38.55.151.63
He also noted a link to ValleyRAT :
Notably, 202.
- 160[. ]201 had previously been observed as command-and-control infrastructure associated with ValleyRAT and Gh0st RAT activity.
