3PARA RAT - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 19:24:34 UTC Home > List all groups > List all tools > List all groups using tool 3PARA RAT Tool: 3PARA RAT Names 3PARA RAT Category Malware Type Backdoor Description (CrowdStrike) The 3Para rat was described in some detail in other Crowdstrike reporting, which examined a dll-based sample with an exported filename of ssdpsvc.dll. Other observed exported filenames are msacem.dll and mrpmsg.dll, although the rat has also been observed in plain executable (EXE) format. Information MITRE ATT&CK Last change to this tool card: 22 April 2020 Download this tool card in JSON format All groups using tool 3PARA RAT Changed Name Country Observed APT groups Putter Panda, APT 2 2007 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8ad145c5-3672-44b3-8e81-3a5b0e7e3d1f https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8ad145c5-3672-44b3-8e81-3a5b0e7e3d1f Page 1 of 1