{"id":41931,"date":"2021-07-09T00:00:00","date_gmt":"2021-07-09T00:00:00","guid":{"rendered":"https:\/\/www.trendmicro.com\/en_us\/research\/21\/g\/biopass-rat-new-malware-sniffs-victims-via-live-streaming.html"},"modified":"2021-07-09T00:00:00","modified_gmt":"2021-07-09T00:00:00","slug":"biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/","title":{"rendered":"BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/biopass-rat-new-malware-sniffs-victims-via-live-streaming\/BIOPASS-RAT-641.png\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/biopass-rat-new-malware-sniffs-victims-via-live-streaming\/BIOPASS-RAT-641.png\" class=\"ff-og-image-inserted\"><\/div>\n<tr>\n<td width=\"372\" valign=\"top\">\n<p>SHA256<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Filename<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Note<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Analysis<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"9\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>84fbf74896d2a1b62d73b9a5d0be2f627d522fc811fe08044e5485492d2d4249<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>big.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (Version 3)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>TrojanSpy.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>f3c96145c9d6972df265e12accfcd1588cee8af1b67093011e31b44d0200871f<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>c1222.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (C1222 module)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>0f8a87ca5f94949904804442c1a0651f99ba17ecf989f46a3b2fde8de455c4a4<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>c1222.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (C1222 module)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>d8b1c4ad8f31c735c51cb24e9f767649f78ef5c571769fbaac9891c899c33444<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>c1222.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (C1222 module)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>ee4150f18ed826c032e7407468beea3b1f738ba80b75a6be21bb8d59ee345466<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>c1222.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (C1222 module)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>34be85754a84cc44e5bb752ee3a95e2832e7be1f611dd99e9a1233c812a6dad2<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>c1222.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (C1222 module)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>30ccfbf24b7c8cc15f85541d5ec18feb0e19e75e1e4d2bca9941e6585dad7bc7<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>cdaemon.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (Cdaemon module)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>f21decb19da8d8c07066a78839ffd8af6721b1f4323f10a1df030325a1a5e159<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>cdaemon.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (Cdaemon module)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>40ab025d455083500bfb0c7c64e78967d4d06f91580912dccf332498681ebaf6<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>cdaemon.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (Cdaemon module)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>e479823aa41d3f6416233dba8e765cf2abaa38ad18328859a20b88df7f1d88d5<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>sc2.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT encoded Cobalt Strike shellcode<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.COBEACON.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>e567fd0f08fdafc5a89c9084373f3308ef464918ff7e4ecd7fb3135d777e946d<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>sc3.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT encoded Cobalt Strike shellcode<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.COBEACON.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>0c8c11d0206c223798d83d8498bb21231bbeb30536a20ea29a5d9273bc63313d<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>s.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT encoded Cobalt Strike shellcode<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.COBEACON.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>2beabd8a9d9a485ab6d850f67ec25abbd66bf97b933ecc13cf0d63198e9ba26e<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>x.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>Python script of Cobalt Strike shellcode loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.COBEACON.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>00977e254e744d4a242b552d055afe9d6429a5c3adb4ba169f302a53ba31795d<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>\ufeff1-CS-443.lua<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>LUA script of Cobalt Strike shellcode loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">Trojan.Win32.COBEACON.BG<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>dbb6c40cb1a49f4d1a5adc7f215e8e15f80b9f0b11db34c84e74a99e41671e06<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Online.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (local online server)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"9\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>943e8c9b0a0a37237ec429cb8a3ff3b39097949e6c57baf43918a34b0110dd8f<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>getwechatdb.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (getwechatdb plugin script)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>TrojanSpy.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"9\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>760fe7645134100301c69289a366bb92ab14927a7fbb9b405c1352989f16488c<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>wechat.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (getwechatdb plugin script)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>TrojanSpy.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>bdf7ebb2b38ea0c3dfb13da5d9cc56bf439d0519b29c3da61d2b2c0ab5bc6011<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>xss_spoof.zip<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT Python Script (xss_spoof plugin package)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Python.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>e3183f52a388774545882c6148613c67a99086e5eb8d17a37158fc599ba8254b<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>x.js<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>XSS watering hole attack script<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.JS.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>d3956e237066a7c221cc4aaec27935d53f14db8ab4b1c018c84f6fccfd5d0058<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>script.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>XSS attack JavaScript payload<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.JS.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>4e804bde376dc02daedf7674893470be633f8e2bda96fa64878bb1fcf3209f60<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>xss.txt<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>XSS attack HTML payload<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.HTML.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>05d1c273a4caeae787b2c3faf381b5480b27d836cd6e41266f3eb505dcee6186<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>09530096643b835cff71a1e48020866fd0d4d0f643fe07f96acdcd06ce11dfa4<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test-ticker.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>0b16dfa3e0bbcc7b04a9a43309e911059a4d8c5892b1068e0441b177960d3eee<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight_ins.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>0f18694b400e14eb995003541f16f75a5afc2478cc415a6295d171ba93565a82<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash_installer.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>11b785e77cbfa2d3849575cdfabd85d41bae3f2e0d33a77e7e2c46a45732d6e4<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>System.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>2243c10b1bd64dfb55eda08bc8b85610d7fa5ba759527b4b4dd16dfac584ef25<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test3.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>281c938448e32eb12fe8c5439ef06cea848668cf57fed5ad64b9a8d1e07de561<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash1.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>2b580af1cdc4655ae75ef503aba7600e05cdd68b056a9354a2184b7fbb24db6f<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight_ins.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>30a65a54acfbf8d412ade728cad86c5c769befa4e456f7c0e552e1ab0862a446<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash-64.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>30d9ffd4b92a4ed67569a78ceb25bb6f66346d1c0a7d6d6305e235cbdfe61ebe<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight_ins.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>3195c355aa564ea66b4b37baa9547cb53dde7cf4ae7010256db92fff0bde873d<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>32a3934d96a8f2dae805fa28355cd0155c22ffad4545f9cd9c1ba1e9545b39ac<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>32c1460ba5707783f1bbaedab5e5eab21d762094106d6af8fa6b2f0f0d777c1a<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test3.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>344cdbc2a7e0908cb6638bc7b81b6b697b32755bad3bed09c511866eff3876c7<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test4.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>3589e53c59d9807cca709387bbcaaffc7e24e15d9a78425b717fc55c779b928e&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>36e3fcd6a4c7c9db985be77ea6394b2ed019332fdae4739df2f96a541ea52617<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>3e8f8b8a5f70c195a2e4d4fc7f80523809f6dbf9ead061ce8ef04fb489a577cf<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test-flash.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>5d7aa3474e734913ecb4b820c0c546c92f7684081c519eecd3990e11a19bf2ba<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash_installer.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>5fd2da648068f75a4a66b08d6d93793f735be62ae88085a79d839b6a0d6d859a<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash1.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>660cef8210f823acb0b31d78fbce1d6f3f8c4f43231286f7ac69f75b2c42c020<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\" readability=\"5\">\n<p>flashplayerpp_install_cn.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>69d930050b2445937ec6a4f9887296928bf663f7a71132676be3f112e80fe275<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>6a0976e5f9d07ff3d80fa2958976183758ba5fcdd4645e391614a347b4b8e64b<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\" readability=\"5\">\n<p>f0b96efe2f714e7bddf76cc90a8b8c88_se.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>6ee8f6a0c514a5bd25f7a32210f4b3fe878d9d417a7ebe07befc285131bae10e<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>news.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>75e03f40a088903579a436c0d8e8bc3d0d71cf2942ad793cc948f36866a2e1ad<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>silverlight_ins.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>7d0d7d416db5bd7201420982987e213a129eef2314193e4558a24f3c9a91a38e<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash_installer.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>7f4e02a041ca7cfbdc79b96a890822fd7c37be67b1f6c9e07596e6aec57ccdc0<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>8445c0189735766edf0e3d01b91f6f98563fef272ac5c92d3701a1174ad072dd<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight_ins.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>89c0b2036ce8d1d91f6d8b8171219aafcd6237c811770fa16edf922cedfecc54<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>MTYwOTI1MzEzNQ==.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>8b5d4840bbdce0798950cd5584e3d4564581a7698bc6cfb2892c97b826129cec<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight_ins.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>932B45AB117960390324678B0696EF0E07D7F8DE1FA0B94C529F243610F1DCC9<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash_ins.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>98a91356e0094c96d81bd27af407dd48c3c91aaf97da6794aeb303597a773749<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight1.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>9eed9a2e0edf38f6354f4e57b3a6b9bed5b19263f54bcee19e66fc8af0c29e4e<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>9f34d28562e7e1e3721bbf679c58aa8f5898995ed999a641f26de120f3a42cf4<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight1.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>9ff906ffcde32e4c6fb3ea4652e6d6326713a7fde8bb783b52f12a1f382f8798<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>a7c4dac7176e291bd2aba860e1aa301fb5f7d880794f493f2dea0982e2b7eb31<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>b48e01ff816f12125f9f4cfc9180d534c7c57ef4ee50c0ebbe445e88d4ade939<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>b82bde3fe5ee900a76ac27b4869ed9aa0802c63bbd72b3bfb0f1abce6340cc6c<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight_ins.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>b9d0838be8952ebd4218c8f548ce94901f789ec1e32f5eaf46733f0c94c77999<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight_ins.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>ba44c22a3224c3a201202b69d86df2a78f0cd1d4ac1119eb29cae33f09027a9a<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight2.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>bd8dc7e3909f6663c0fff653d7afbca2b89f2e9bc6f27adaab27f640ccf52975<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>bf4f50979b7b29f2b6d192630b8d7b76adb9cb65157a1c70924a47bf519c4edd<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>c11906210465045a54a5de1053ce0624308a8c7b342bb707a24e534ca662dc89<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test-flash.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>c3fa69e15a63b151f8d1dc3018284e153ad2eb672d54555eaeaac79396b64e3b<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>c47fabc47806961f908bed37d6b1bbbfd183d564a2d01b7cae87bd95c20ff8a5<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\" readability=\"5\">\n<p>flashplayerpp_install_cn.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>c8542bffc7a2074b8d84c4de5f18e3c8ced30b1f6edc13047ce99794b388285c<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash2.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>cce6b17084a996e2373aaebbace944a17d3e3745e9d88efad4947840ae92fd55<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight_ins.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>d18d84d32a340d20ab07a36f9e4b959495ecd88d7b0e9799399fcc4e959f536b<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash_installer.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>e4109875e84b3e9952ef362abc5b826c003b3d0b1b06d530832359906b0b8831<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>e52ea54cfe3afd93a53e368245c5630425e326291bf1b2599b75dbf8e75b7aeb<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\" readability=\"5\">\n<p>flashplayer_install_cn.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>f1ad25b594a855a3c9af75c5da74b44d900f6fbb655033f9a98a956292011c8e<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Silverlight.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>fa1d70b6b5b1a5e478c7d9d840aae0cc23d80476d9eea884a73d1b7e3926a209<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>64.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>fa7fbca583b22d92ae6d832d90ee637cc6ac840203cd059c6582298beb955aee<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>fb770a3815c9ebcf1ba46b75b8f3686acc1af903de30c43bab8b86e5b46de851<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>test4.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>fb812a2ccdab0a9703e8e4e12c479ff809a72899374c1abf06aef55abbbf8edc<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash_installer.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>BIOPASS RAT Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Backdoor.Win64.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>ee2e9a1d3b593fd464f885b734d469d047cdb1bc879e568e7c33d786e8d1e8e2<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>aos.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (PyInstaller)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>afbfe16cbdd574d64c24ad97810b04db509505522e5bb7b9ca3b497efc731045<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>socketio.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (Nuitka)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>0b9f605926df4ff190ddc6c11e0f5839bffe431a3ddfd90acde1fcd2f91dada3<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>socketio.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (Nuitka)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>6fc307063c376b8be2d3a9545959e068884d9cf7f819b176adf676fc4addef7d<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>flash_ins_bak.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (Nuitka)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>7249ad971283e164b0489110c23f4e40c64ee49b49bcc5cd0d32d9e701ec2114<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>files.zip<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (Nuitka)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>de17e583a4d112ce513efd4b7cb575d272dcceef229f81360ebdfa5a1e083f11<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>fn.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (Nuitka)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>17e43d31585b4c3ac6bf724bd7263761af75a59335b285b045fce597b3825ed0<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>systemsetting.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (PyInstaller)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>b3bd28951789ef7cfaf659e07e198b45b04a2f3cde268e6ede4d4f877959341e<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>systemsetting.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (PyInstaller)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>e0caebfbd2804fcde30e75f2c6d06e84b3bf89ed85db34d6f628b25dca7a9a0f&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>YIZHI_SIGNED.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (PyInstaller)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>2503549352527cb0ffa1811a44481f6980961d98f9d5a96d5926d5676c31b9ee<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>socketio.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (Nuitka)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"9\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>8ba72a391fb653b2cc1e5caa6f927efdf46568638bb4fc25e6f01dc36a96533b<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\" readability=\"5\">\n<p>flashplayerpp_install_cn.exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>BIOPASS RAT binary (Nuitka)<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win32.BIOPASS.A<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>e5fdb754c1a7c36c288c46765c9258bb2c7f38fa2a99188a623182f877da3783<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>beep.sys<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Derusbi<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Trojan.Win64.DERUSBI.C<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"372\" valign=\"top\" readability=\"5\">\n<p>a7e9e2bec3ad283a9a0b130034e822c8b6dfd26dda855f883a3a4ff785514f97<\/p>\n<\/td>\n<td width=\"252\" valign=\"top\">\n<p>Browser_plugin (8).exe<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\">\n<p>Cobalt Strike Loader<\/p>\n<\/td>\n<td width=\"0\" valign=\"top\" readability=\"5\">\n<p>Trojan.Win64.COBEACON.SUX<\/p>\n<\/td>\n<\/tr>\n<p>Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/g\/biopass-rat-new-malware-sniffs-victims-via-live-streaming.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We discovered a new malware that targets online gambling companies in China via a watering hole attack, in which visitors are tricked into downloading a malware loader disguised as a legitimate installer for well-known apps such as Adobe Flash Player or Microsoft Silverlight. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":41932,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9471,9461,378,28,842],"class_list":["post-41931","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-apttargeted-attacks","tag-articles-news-reports","tag-endpoints","tag-malware","tag-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-09T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher.png\" \/>\n\t<meta property=\"og:image:width\" content=\"641\" \/>\n\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher\",\"datePublished\":\"2021-07-09T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/\"},\"wordCount\":2325,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher.png\",\"keywords\":[\"APT&amp;Targeted Attacks\",\"Articles, News, Reports\",\"endpoints\",\"Malware\",\"Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/\",\"name\":\"BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher.png\",\"datePublished\":\"2021-07-09T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher.png\",\"width\":641,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"APT&amp;Targeted Attacks\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/apttargeted-attacks\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/","og_locale":"en_US","og_type":"article","og_title":"BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-07-09T00:00:00+00:00","og_image":[{"width":641,"height":350,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher","datePublished":"2021-07-09T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/"},"wordCount":2325,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher.png","keywords":["APT&amp;Targeted Attacks","Articles, News, Reports","endpoints","Malware","Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/","url":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/","name":"BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher.png","datePublished":"2021-07-09T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher.png","width":641,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/biopass-rat-new-malware-sniffs-victims-via-live-streaming-threat-researcher-threat-researcher-threat-researcher-threat-researcher\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"APT&amp;Targeted Attacks","item":"https:\/\/www.threatshub.org\/blog\/tag\/apttargeted-attacks\/"},{"@type":"ListItem","position":3,"name":"BIOPASS RAT: New Malware Sniffs Victims via Live Streaming Threat Researcher Threat Researcher Threat Researcher Threat Researcher"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41931","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=41931"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41931\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/41932"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=41931"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=41931"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=41931"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}