MetaRAT is a malware family used by threat actors to gain remote access to compromised systems.
MetaRAT is a malware family used by threat actors to gain remote access to compromised systems. Recent activity shows it being deployed through exploits targeting Ivanti Connect Secure VPN appliances, highlighting the risk of exposed VPN infrastructure and the importance of promptly patching vulnerabilities and monitoring for intrusions. The campaigns indicate a focus on delivering backdoor capabilities via VPN vulnerabilities to establish footholds in targeted networks.
A China-based advanced persistent threat (APT) group has exploited vulnerabilities in Ivanti Connect Secure to deploy MetaRAT malware. Japan's cybersecurity firm LAC has confirmed the targeted nature of this attack,…