#ParsedReport #CompletenessHigh
24-09-2026
LxBase RAT Observed for the First Time in Attacks on Russian Companies
https://bi.zone/expertise/blog/lxbase-rat-vpervye-zamechen-v-atakakh-na-rossiyskie-kompanii/
Report completeness: High
Threats:
Lxbaserat
Lx-rat
Hvnc_tool
Spear-phishing_technique
Process_injection_technique
Victims:
Finance, Engineering, Manufacturing, Energy, Retail, Agriculture, Logistics, Construction, Information technology
Industry:
Financial, Retail, Logistic, Foodtech, Energy
Geo:
Russian, Russia
TTPs:
Tactics: 9
Technics: 0
IOCs:
File: 13
Domain: 2
Hash: 26
IP: 1
Path: 2
Command: 2
Coin: 1
Registry: 2
Soft:
Chrome, Chrome Canary, Opera, Opera GX, Vivaldi, Yandex Browser, ch, Com, odo Dragon, SRW, are Iron, Epi, c Privacy Browser, Cen, have more...
Wallets:
atomicwallet, jaxx, coinomi, guarda_wallet, electrum, zcash, wassabi, metamask, tronlink, coin98, have more...
Crypto:
bitcoin, litecoin, ethereum, monero, binance
Algorithms:
deflate, aes, xor, cbc
Functions:
GetProcessesRequest, GetStartupItems, GetSystemInfoRequest, Remove-Item
Win API:
ZONE, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, ResumeThread, decompress
Languages:
javascript, visual_basic, powershell
Platforms:
x86, x64
Post #32723
26