Overview
Two UK based universities were discovered to have Remote Access Trojan (RAT) in their network within the last two months. It is realistically probable that both RATs within the universities were placed by the same threat actor based on timings and code sharing. This may be indicative of an escalation in targeting within the higher education sector. Following the analysis by Quorum Cyber’s Threat Intelligence (QCTI) team, we are tracking this malware as NodeSnake.

Download this report






