ObliqueRAT is yet another remote access Trojan that is distributed via malicious Microsoft Word macro enabled documents. Which pave the way for the original malicious executable, the RAT itself. It has all the vanilla RAT features like, downloading additional files, running arbitrary commands, communication covertly with its command and control server, maintaining persistence and other RAT stuff. Cisco suggests that it appear to be similar with CrimsonRAT. It might be its next version/iteration.
ObliqueRAT Malicious Document Signatures
Family: Trojan:Win32/Casdet!rfn
MD5: f2dddba78eeba2eba586b945168a1935
SHA256: 057da080ae0983585ae21195bee60d82664355a7fd78c25f21791b165c250212
ObliqueRAT Malicious Document Download
ObliqueRAT Executable Signatures
Family: Trojan:Win32/Casdet!rfn
MD5: 36903d471c43b5d602aefd791e25c889
SHA256: 37c7500ed49671fe78bd88afa583bfb59f33d3ee135a577908d633b4e9aa4035
ObliqueRAT Executable Download