Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 21:33:15 UTC Home > List all groups > List all tools > List all groups using tool CARROTBALL Tool: CARROTBALL Names CARROTBALL Category Malware Type Dropper Description (Palo Alto) CARROTBALL, initially discovered in an attack during October 2019, is a simple FTP downloader utility which facilitates the installation of Syscon, a full-featured Remote Access Trojan (RAT) which leverages FTP for Command and Control (C2). It was found embedded in a malicious Word document sent as a phishing lure to a US government agency and two non-US foreign nationals professionally associated with North Korea. Information MITRE ATT&CK Malpedia AlienVault OTX Last change to this tool card: 30 December 2022 Download this tool card in JSON format All groups using tool CARROTBALL Changed Name Country Observed APT groups Reaper, APT 37, Ricochet Chollima, ScarCruft 2012-Mar 2025 1 group listed (1 APT, 0 other, 0 unknown) https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9ab63043-dd17-4e16-97af-d79d55b5c5da Page 1 of 2 Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9ab63043-dd17-4e16-97af-d79d55b5c5da https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9ab63043-dd17-4e16-97af-d79d55b5c5da Page 2 of 2