Yet another RAT in town: RemoteX ๐ฅ๏ธ
๐ชฒ Dropped by Amadey
๐ Written in Golang
๐ป Uses HKCU\...\CurrentVersion\Run\RemoteX for persitence (lame ๐ฝ)
๐ Uses WebSocket for C2 communication
๐ต๏ธโโ๏ธ Unauthenticated RAT admin panel ๐คก
Botnet C2:
๐ก 109.107.168.147:80 (Partner Hosting LTD ๐ฌ๐ง)
Malware sample โคต๏ธ
https://bazaar.abuse.ch/sample/d631655ad3ef9e7c854c86ae399a9c830bef784c6a51468d192f65a79bbb7c8b/

