malware
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
High
Summary
A new remote access trojan (RAT) called ChocoPoC is targeting vulnerability researchers through deceptive proof-of-concept (PoC) repositories on GitHub. The malware, disguised within Python dependencies, steals sensitive data like passwords, browser cookies, and files, leveraging the researchers' eagerness to quickly test newly disclosed vulnerabilities. This tactic, combined with the malware's ability to blend in with legitimate code, poses a significant risk to security professionals and highlights a novel delivery mechanism for established malware.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
