PULSE NAME
RTF Exploit Installs RAT: uWarrior
WHITE AlienVault 2026-04-24 Modified: 2026-04-24
8
IOCs
LOW VOLUME
An unknown Italian-origin threat actor has developed uWarrior, a Remote Access Tool delivered through weaponized RTF documents containing multiple exploits. The attack chain leverages CVE-2012-1856 with a novel ROP chain and CVE-2015-1770 to bypass ASLR protections by loading non-DYNAMICBASE compiled DLLs through OLE objects. The fully-featured RAT uses compressed, optionally encrypted TCP communications with binary message protocols for command and control. Analysis reveals the actor borrowed components from off-the-shelf tools, particularly the ctOS RAT, sharing similar configuration structures and code functions. uWarrior provides extensive capabilities including remote command execution, file manipulation, system control, software enumeration and uninstallation, and data exfiltration. The malware establishes persistence and communicates with C2 servers using AES encryption.
Indicators of Compromise (2 / 8 total)
All CVE FileHash-SHA256 IPv4 hostname
TYPEINDICATORDESCRIPTIONCREATED
hostname login.collegefan.org 2026-04-24
hostname login.loginto.me 2026-04-24