Last seven days
- First activity
- Sep 16, 2026
- Last activity
- Sep 17, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
Poco RAT is a remote access trojan used in campaigns against Spanish-speaking organizations in Latin America, including the mining sector.
Profile source: Mallory opens in a new tabPoco RAT
Poco RAT is a remote access trojan used in campaigns against Spanish-speaking organizations in Latin America, including the mining sector. Activity distributing the malware has been attributed to Dark Caracal, also known as Darkling APT, an espionage-focused threat actor. Documented campaigns use phishing emails with malicious PDF attachments that direct recipients to download intermediate files from file-sharing services; those files execute droppers that install Poco RAT. The malware provides remote control of compromised endpoints, supports command execution, and collects system information. Dark Caracal has also distributed Poco RAT through financial-themed phishing as part of cyber-espionage operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
32c899c7e05d0403701028796d95e58c0571e694704685cc438ec2a14a1a9976 4e17f6ec42ef438a2223bc422c8ce775fbe7871bf998e69855198e68fdcba70f 82d570622b7950e650840e1e00b09ab5a937c1a0308b05611104e746f6ae9dc2 0104d77be6a8126bf8a0893c2b1a3997f96bd69a104163b63c35fdd1b2152a25 c64c8d77493b0d4c5949cec8da3c182af9f18482602ed92eaa32455f0d855c11 Reported operators
A new campaign distributing Poco RAT to Spanish-speaking users in Latin America has been reported in the wild.
A new campaign distributing Poco RAT to Spanish-speaking users in Latin America has been reported in the wild.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.