Skip to content

Poco RAT

Poco RAT is a remote access trojan used in campaigns against Spanish-speaking organizations in Latin America, including the mining sector.

Profile source: Mallory opens in a new tab

Poco RAT

Family profile

Poco RAT is a remote access trojan used in campaigns against Spanish-speaking organizations in Latin America, including the mining sector. Activity distributing the malware has been attributed to Dark Caracal, also known as Darkling APT, an espionage-focused threat actor. Documented campaigns use phishing emails with malicious PDF attachments that direct recipients to download intermediate files from file-sharing services; those files execute droppers that install Poco RAT. The malware provides remote control of compromised endpoints, supports command execution, and collects system information. Dark Caracal has also distributed Poco RAT through financial-themed phishing as part of cyber-espionage operations.

Capabilities

  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 16, 2026
Last activity
Sep 17, 2026
Feed role
C2
Host form
2 IP / 0 hostnames

Leading locations

  • MD1
  • RO1

Leading providers

  • ALEXHOST SRL1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Dark Caracal

A new campaign distributing Poco RAT to Spanish-speaking users in Latin America has been reported in the wild.

Darkling APT

A new campaign distributing Poco RAT to Spanish-speaking users in Latin America has been reported in the wild.

MITRE ATT&CK

Poco RAT in ATT&CK

7 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.