Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

How to Detect Yellow Cockatoo Remote Access Trojan

released on 2020-12-04 @ 10:26:41 PM
This summer, Red Canary Intel detected a cluster of malicious activity executing a .NET RAT across multiple industries. Yellow Cockatoo is Red Canary's name for a cluster of activity involving the execution of a .NET remote access trojan (RAT) that runs in memory and drops other payloads. Red Canary has been tracking this threat since June 2020. Yellow Cockatoo has targeted a range of victims across multiple industries and company sizes, and we continue to see it, as recently as this week. This blog focuses on how to detect Yellow Cockatoo RAT activity.