Malware Alert New Kedi RAT Uses Gmail to Exfiltrate Data

    Kedi RAT Pretends to be a Citrix Utility, Transfers Data Using Gmail

    A newly discovered remote access Trojan (RAT) capable of evading security scanners communicates with its command and control (C&C) server via Gmail, Sophos has discovered.

    Dubbed Kedi, the RAT was designed to steal data and is being spread via spear-phishing emails, the security researchers say. The observed attacks appear targeted with the malicious payload masquerading as a Citrix utility.

