
ModeloRAT campaign leverages Microsoft Teams phishing to deploy Python-based RAT, escalate via CVE-2023-36036, and harvest domain credentials through fake lock screen. Two-day progression from initial contact to full domain compromise. Key technical details: • Initial access via fake "IT Support" Teams message from UCICasociacion.onmicrosoft[.]com tenant • PowerShell stager downloads portable WinPython + ModeloRAT from Dropbox to %APPDATA% • Privilege escalation using CVE-2023-36036 (cldflt.sys heap overflow) - custom exploit targeting Cloud Files driver • Credential harvesting via fake Windows lock screen DLL (com6848.dll) deployed after SYSTEM access • Multiple C2 channels: HTTP beacons (46.225.231[.]170, 144.172.99[.]68), TCP shells, SOCKS5 proxies Attack progression: • Teams social engineering → PowerShell execution → Python RAT deployment (T1566.003, T1059.001) • Host reconnaissance via http://collector.py saves results to %TEMP%\configA.json • CVE-2023-36036 exploit registers fake "PLURIBUS" sync provider, shapes kernel heap via WNF APIs • WebDAV credential spraying using davclnt.dll DavSetCookie API for stealthy validation • RDP lateral movement + memory dump via DumpIt.exe, exfiltrated through uploadnow[.]io Hunt for WinPython in %APPDATA%, fake Cloud Files sync providers in Registry (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager\PLURIBUS), and WebDAV authentication attempts via rundll32.exe davclnt.dll. #DFIR_Radar
Post summary
ModeloRAT demonstrates active exploitation of CVE-2023-36036 via a custom heap‑overflow exploit, leveraging Microsoft Teams phishing to stage a Python RAT, harvest credentials, and maintain persistence across a compromised domain.

