#ResolverRAT
Morphisec has identified a new remote access trojan used in the wild named ResolverRAT.

Looks more advanced than the usual RATs, from their write-up.

www.morphisec.com/blog/new-mal...
New Malware Variant Identified: ResolverRAT Enters the Maze
Morphisec identifies ResolverRAT, a remote access trojan with advanced capabilities and layered evasion techniques. Read on for a full threat analysis.
www.morphisec.com
April 15, 2025 at 8:58 AM
-Malicious WhatsApp apps stole $600,000
-New PasivRobber macOS spyware, Gorilla banking trojan, ResolverRAT, Storm-1811 backdoor
-Major Apache Roller session bug
-Oracle CPU is out
-Android auto-restart for locked devices roll out
-New tool—FindUnusualSessions
April 16, 2025 at 8:47 AM
ResolverRAT is hitting healthcare and pharma sectors hard — phishing, fear-bait, stealth attacks.

🛡️ Sophisticated multi-stage RAT
🌐 Localized lures: Hindi, Italian, Turkish + more
🕵️‍♂️ Advanced evasion: encryption, IP rotation, memory-only payload
#CyberAttacks
thehackernews.com/2025/04/reso...
ResolverRAT Campaign Targets Healthcare, Pharma via Phishing and DLL Side-Loading
ResolverRAT targets healthcare and pharma via localized phishing; uses advanced stealth tactics to ensure persistence and evade detection.
thehackernews.com
April 14, 2025 at 9:16 PM
New Malware ResolverRAT Targets Healthcare and Pharma Sectors buff.ly/7arFuCa
New Malware ResolverRAT Targets Healthcare and Pharma Sectors
ResolverRAT targets healthcare organizations using advanced evasion techniques and social engineering
buff.ly
April 15, 2025 at 9:12 AM
New Malware Variant Identified: ResolverRAT Enters the Maze
www.morphisec.com/blog/new-mal...
New Malware Variant Identified: ResolverRAT Enters the Maze
Morphisec identifies ResolverRAT, a remote access trojan with advanced capabilities and layered evasion techniques. Read on for a full threat analysis.
www.morphisec.com
April 15, 2025 at 11:35 AM
New ResolverRAT malware targets pharma and healthcare orgs worldwide buff.ly/VSYHRXz
New ResolverRAT malware targets pharma and healthcare orgs worldwide
A new remote access trojan (RAT) called 'ResolverRAT' is being used against organizations globally, with the malware used in recent attacks targeting the healthcare and pharmaceutical sectors.
buff.ly
April 14, 2025 at 11:42 PM
Les employés des entreprises visées reçoivent un courriel évoquant des violations légales ou du droit d’auteur. Ces motifs sont susceptibles d’éveiller la curiosité des cibles et d’endormir leur méfiance. www.01net.com/actualites/c...
Cyberattaque mondiale : le virus ResolverRAT prend d'assaut le secteur de la santé et de la pharmacie
Un nouveau virus du nom de ResolverRAT se propage dans le monde entier. Le malware piège les entreprises du secteur de la santé et de la pharmacie avec des mails de phishing calibrés. Au terme de l'at...
www.01net.com
April 15, 2025 at 9:37 PM
A new remote access trojan (RAT) called 'ResolverRAT' is being used against organizations globally, with the malware used in recent attacks targeting the healthcare and pharmaceutical sectors.
New ResolverRAT malware targets pharma and healthcare orgs worldwide
A new remote access trojan (RAT) called 'ResolverRAT' is being used against organizations globally, with the malware used in recent attacks targeting the healthcare and pharmaceutical sectors.
www.bleepingcomputer.com
April 14, 2025 at 4:40 PM
Cyberattaque mondiale : le virus ResolverRAT prend d’assaut le secteur de la santé et de la pharmacie www.01net.com/actualites/c...
April 15, 2025 at 8:55 AM
How to identify #PureRAT (aka #ResolverRAT):
⛳️ C2 port is often 56001, 56002 or 56003
🔢 Bot sends 04 00 00 00, then TLS handshake
🔑 Client and server run TLS 1.0
🖊️ X.509 cert is self signed
📅 X.509 cert expires 9999-12-31
netresec.com?b=2589522
PureRAT = ResolverRAT = PureHVNC
PureRAT is a Remote Access Trojan, which can be used by an attacker to remotely control someone else's PC. PureRAT provides the following features to an attacker: See the victims user interfaceInt...
netresec.com
August 12, 2025 at 6:20 PM
The broken TLS implementation in `PureRAT` has been described in our blog post PureRAT = ResolverRAT = PureHVNC. Examples of such broken TLS traffic to `196.251.86.238:56001` can be found on JoeSandbox and ANY.RUN.
PureRAT = ResolverRAT = PureHVNC
PureRAT is a Remote Access Trojan, which can be used by an attacker to remotely control someone elses PC. PureRAT provides the following features to an attacker: See the victims user interfaceInteract with the victim PC using mouse and keyboardView the webcamListen to the microphoneRecord keystrokes[...]
www.netresec.com
July 30, 2026 at 3:10 PM
Notícia da BleepingComputer

"New ResolverRAT malware targets pharma and healthcare orgs worldwide" #bolhasec
New ResolverRAT malware targets pharma and healthcare orgs worldwide
A new remote access trojan (RAT) called 'ResolverRAT' is being used against organizations globally, with the malware used in recent attacks targeting the healthcare and pharmaceutical sectors.
www.bleepingcomputer.com
July 5, 2025 at 6:30 PM
Notícia da SecurityWeek

"New ‘ResolverRAT’ Targeting Healthcare, Pharmaceutical Organizations" #bolhasec
New 'ResolverRAT' Targeting Healthcare, Pharmaceutical Organizations
Organizations in the healthcare and pharmaceutical sectors have been targeted with ResolverRAT, a new malware family with advanced capabilities.
www.securityweek.com
May 19, 2025 at 3:30 PM
New ResolverRAT malware targets healthcare & pharma firms globally, stealing sensitive data via sophisticated phishing attacks. #Cybersecurity #Malware #Infosec
New ResolverRAT Malware Targets Pharma Healthcare Firms
New ResolverRAT malware targets healthcare & pharma firms globally, stealing sensitive data via sophisticated phishing attacks. #Cybersecurity #Malware #Infosec
securityaffairs.com
April 15, 2025 at 1:07 PM
“ResolverRAT Campaign Targets Healthcare, Pharma via Phishing and DLL Side-Loading” — The Hacker News

#PhishingNews #Phishing #AI
April 14, 2025 at 6:35 PM
Privacidade vs. Farmácias | Grande Firewall das Facções | Mais RMM contra o Brasil: Atera Agent | ResolverRAT

zerodia.substack.com/p/zero-dia-s...
ZERO DIA - Semana 2025-04-12
Privacidade vs. Farmácias | Grande Firewall das Facções | Mais RMM contra o Brasil: Atera Agent | ResolverRAT
zerodia.substack.com
April 22, 2025 at 8:49 AM
New ResolverRAT Malware Targets Healthcare and Pharma Sectors Worldwide #Cybersecurity #malware #Malwareanalysis
New ResolverRAT Malware Targets Healthcare and Pharma Sectors Worldwide
  A newly discovered remote access trojan (RAT), dubbed ResolverRAT, is being actively used in targeted cyberattacks against healthcare and pharmaceutical entities across various countries. Identified by cybersecurity researchers at Morphisec, the malware is delivered through phishing emails and uses in-memory execution tactics that allow it to bypass most traditional endpoint security solutions. The attack campaign is tailored to different regions, with phishing messages crafted in native languages such as Czech, Italian, Turkish, Hindi, Portuguese, and Indonesian. These deceptive emails often reference legal or copyright-related issues to lure users into clicking malicious links. Victims unknowingly download a legitimate executable, hpreader.exe, which is manipulated through a technique called reflective DLL loading—executing the malicious code entirely in memory. Morphisec researchers note that the attack leverages DLL side-loading: by placing a malicious DLL alongside a trusted but vulnerable application, the malware is executed when the genuine software is launched. Further, ResolverRAT exploits the .NET ‘ResourceResolve’ event to load malicious assemblies, avoiding typical flagged API calls. “This resource resolver hijacking represents malware evolution at its finest – utilizing an overlooked .NET mechanism to operate entirely within managed memory, circumventing traditional security monitoring focused on Win32 API and file system operations,” wrote Morphisec’s Nadav Lorber in a blog. ResolverRAT is equipped with multiple anti-analysis capabilities. It features a complex state machine that obfuscates its control flow and fingerprints system behaviors, making it difficult for sandboxes and debugging tools to detect or analyze. To maintain persistence, the malware writes XOR-obfuscated keys into up to 20 Windows registry entries and replicates itself in directories such as Startup and LocalAppData. It connects to its command-and-control (C2) server at irregular intervals, further concealing its network activity from pattern-based detection tools. The RAT handles commands using separate threads, which enables parallel task execution and reduces crash risks. For data exfiltration, it employs a chunked transfer method—splitting files larger than 1MB into smaller 16KB segments sent only when the socket is ready, a strategy that supports stealth and transfer recovery in poor network conditions. ResolverRAT encrypts its payload with AES-256 in CBC mode via the .NET System.Security.Cryptography library. The keys and IVs are obfuscated and only decoded at runtime. Additionally, the payload is compressed using GZip and runs exclusively in memory to minimize detection risk. While some of the phishing infrastructure resembles earlier Rhadamanthys and Lumma campaigns, Morphisec emphasized that the unique design of ResolverRAT's loader and payload warrants its classification as a new malware strain.
dlvr.it
April 25, 2025 at 4:02 PM
Il ne déclenche aucune alerte et ne laisse rien quasiment traîner sur le disque. Pourtant, ce cheval de Troie peut bel et bien accorder un accès complet à votre machine. Et a priori, il s’en sort plutôt bien. www.clubic.com/actualite-56...
Alerte virus en cours : méfiez-vous de ResolverRAT, le malware qui passe (presque) inaperçu
Il ne déclenche aucune alerte et ne laisse rien quasiment traîner sur le disque. Pourtant, ce cheval de Troie peut bel et bien accorder un accès complet à votre machine. Et a priori, il s’en sort plut...
www.clubic.com
April 15, 2025 at 8:03 PM
>PureRAT is the exact same malware as what Morphisec and others call ResolverRAT. PureHVNC, on the other hand, is the predecessor to PureRAT.
IOCs:
👾 193.26.115.125:8883
👾 purebase.ddns[.]net:8883
👾 45.74.10.38:56001
👾 139.99.83.25:56001
https://netresec.com/?b=2589522
@netresec
netresec.com
August 12, 2025 at 3:48 PM