PULSE NAME
RTF Exploit Installs RAT: uWarrior
WHITE AlienVault 2026-04-24 Modified: 2026-04-24
8
IOCs
LOW VOLUME
An unknown Italian-origin threat actor has developed uWarrior, a Remote Access Tool delivered through weaponized RTF documents containing multiple exploits. The attack chain leverages CVE-2012-1856 with a novel ROP chain and CVE-2015-1770 to bypass ASLR protections by loading non-DYNAMICBASE compiled DLLs through OLE objects. The fully-featured RAT uses compressed, optionally encrypted TCP communications with binary message protocols for command and control. Analysis reveals the actor borrowed components from off-the-shelf tools, particularly the ctOS RAT, sharing similar configuration structures and code functions. uWarrior provides extensive capabilities including remote command execution, file manipulation, system control, software enumeration and uninstallation, and data exfiltration. The malware establishes persistence and communicates with C2 servers using AES encryption.
Indicators of Compromise (8)
All CVE FileHash-SHA256 IPv4 hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2012-1856 2026-04-24
CVE CVE-2015-1770 2026-04-24
FileHash-SHA256 57a5d0da72655df9c5ca9137df7210b86845eeabae488537c70e36587274937c 2026-04-24
FileHash-SHA256 5dce01ec5e1bc1b4f5012e0b4bf16532206284fc8c64cfb8dcf907f45caf98fc 2026-04-24
FileHash-SHA256 a6dea088c9e2c9191e4c2fc4ece7b7b7bd3f034f444362d35c8765f6ec4bd279 2026-04-24
IPv4 63.142.245.12 2026-04-24
hostname login.collegefan.org 2026-04-24
hostname login.loginto.me 2026-04-24