Skip to main content

Tag: rat

17 articles

A cluttered Cambodian office desk with a laptop and smartphone, laptop screen blank.

Spark RAT Campaign Targets Cambodia, Abuses OPSWAT Driver to Disable Security Tools

A new Spark RAT campaign is targeting Cambodia, using clever tactics like phishing emails and signed DLLs to disable security tools and sneak malicious payloads into victims' systems. The attackers are casting a wide net with diverse lure themes, trying to catch as many unsuspecting victims as possible.

Analyst 207
Government office in Central Asia with a laptop and papers on a desk, hinting at technology integration.

China-linked SilkParasite campaign targets Central Asia with custom RATs

Meet SilkParasite, a sneaky espionage operation linked to China that's been targeting government bodies in Central Asia with a custom arsenal of Remote Access Tools. This sophisticated campaign boasts seven unique RAT families, five of which have never been seen before, and hints at AI-assisted development.

Analyst 207
Person sits in dimly lit living room, staring at blank smartphone screen with a somber expression.

Malware Combo Targets Android Users With Loans, Credit Card Theft

In just 13 minutes, a sophisticated scam combining malware and social engineering tricked Android users into handing over their accounts and credit card info, with the thieves monetizing stolen cards in real time. The attack started with a convincing phone call from someone posing as a bank employee, leading victims to unwittingly download a remote administration tool masquerading as a legitimate app.

Analyst 207
Person surrounded by cluttered financial documents holds a smartphone.

WindRelay Malware Enables Live-Call Loan Fraud via NFC Relay Attack

In just 13 minutes, a scammer can use a single phone call to trick victims into installing malware, allowing them to commit card and loan fraud - all thanks to the cunning WindRelay malware. This sneaky software uses NFC relay attacks to enable live-call loan fraud, leaving victims none the wiser.

Analyst 207
Cluttered software development workspace with laptop and terminal on a desk.

Malicious npm Packages Deliver Cross-Platform Malware

Nearly 800 malicious npm packages have been discovered delivering a potent cross-platform malware payload, including a remote access trojan and infostealer, via a sneaky trick that tricks developers into loading the malicious code. These packages use cleverly crafted names and README instructions to evade detection and deploy the WEL1DROPPER downloader.

Analyst 207
Person working on laptop in quiet library space with blurred screen.

Russian Loader Service Exploits Browser Cache to Deliver Malware

Meet DOUBLECUP, a sneaky Russian loader service that's been hiding in plain sight since June 2026, using browser cache tricks to deliver malware to unsuspecting victims. Its clever ClickFix campaigns conceal malicious code within innocent-looking PNG images, deploying nasty payloads like CountLoader and DeviceManager RAT on Windows and macOS devices.

Analyst 207
Young gamer sits in cluttered bedroom with laptop showing Roblox game and nearby screen with Discord chat or gaming forum.

Malware Campaign Targets Roblox with RAT and Infostealer via Fake Xeno Script Launcher

Roblox players beware: a sneaky malware campaign has been targeting gamers with a fake Xeno Script Launcher, infecting them with a RAT and infostealer since the start of the year. The malware was cleverly spread through gaming forums, Discord, and compromised accounts, masquerading as an "undetected" cheat to evade Roblox's anti-cheat protections.

Analyst 207
Cybercrime investigator's lab workbench with laptop, notes, and equipment.

Dolphin X Stealer Uses AI to Target High-Value Victims

Meet Dolphin X Stealer, a sneaky new Windows malware that's packing some serious AI-powered punch, allowing cybercriminals to zero in on high-value targets with ease. Its operator panel boasts an impressive 329 features, giving attackers an unprecedented level of control and insight.

Analyst 207
Laptop on cluttered desk with scattered papers and office supplies.

Windows Stealer Malware Targets 300+ Apps with AI-Powered Profiler

Meet Dolphin X, a sneaky Windows malware that's taking the cybercrime world by storm with its AI-powered profiler and unparalleled ability to infiltrate over 300 apps, swiping sensitive info like browser passwords, crypto wallets, and cloud tokens. This info-stealer is being sold on the dark web as a potent tool for hackers to get their hands on valuable data.

Analyst 207
Windows host computer on an office workstation with a blurred desktop screen.

LabubaRAT Exploits NVIDIA Disguise to Control Windows Hosts

Meet LabubaRAT, a sneaky threat that masquerades as NVIDIA software to take control of Windows hosts, allowing hackers to profile, capture, and manipulate sensitive data. Once deployed, it creates a hidden backdoor for further malicious activity.

Analyst 207
Blurred laptop screen showing Microsoft Teams on a plain surface with office supplies nearby.

Ransomware Gang Exploits Microsoft Teams to Conceal Malicious Traffic

Meet Backdoor.Turn, a sneaky new malware that's abusing Microsoft Teams to hide its malicious activities - and it's a game-changer for cyber threats. This clever RAT uses Teams' own infrastructure against us, making it harder to spot its secret communications.

Analyst 207
Discarded Android smartphones and tech components litter a dimly lit urban alleyway.

ESET Exposes BTMOB Android Malware Service

Meet BTMOB, a sneaky Android malware that's being sold as a subscription service - think $700/month or a one-time $5,000 fee for a lifetime license - making it easy for anyone to become a cyber threat actor. This malware-as-a-service platform even comes with a user-friendly APK builder, requiring zero coding skills.

Analyst 207
Brightly-lit financial sector setting with computer workstation in background.

Lazarus Group Deploys Memory-Only RAT in Financial Sector Attacks

The notorious Lazarus Group has unleashed a sneaky new attack tool, a memory-only Remote Access Trojan (RAT), targeting the financial sector with cunning precision. This stealthy malware, known as RemotePE, is just the latest weapon in the group's arsenal, and it's being used to infiltrate and manipulate its victims.

Analyst 207
Windows laptop on cluttered desk with smartphone nearby, displaying blurred login screen.

CloudZ Malware Exploits Phone Link to Harvest SMS OTPs

Beware of CloudZ malware, a sneaky Windows threat that's been stealing SMS messages and one-time passwords since January 2026 by exploiting Microsoft's Phone Link app. This malicious duo, paired with the Pheno plugin, can capture mobile authentication data without ever touching your smartphone.

Analyst 207
Windows laptop with Phone Link app open, connected to smartphone via USB, on a cluttered home office desk.

CloudZ Malware Exploits Microsoft Phone Link to Harvest SMS and OTPs

Beware: CloudZ malware is exploiting Microsoft's Phone Link feature to intercept SMS and OTPs, putting your sensitive info at risk. This sneaky attack uses a plugin called Pheno to tap into your Phone Link activity and steal your private messages.

Analyst 207
Windows computer workstation in an office setting with router and cables, and a blank laptop screen on the desk.

Python Backdoor Exploits Tunneling Service to Harvest Browser, Cloud Credentials

Meet DEEP#DOOR, a sneaky Python-based backdoor framework that's harvesting browser and cloud credentials by exploiting a tunneling service, and learn how it infiltrates systems through a clever sequence of stealthy steps. This sophisticated threat starts with a simple batch script that disables Windows security controls and ends with a fully featured Remote Access Trojan (RAT).

Analyst 207

New Trojan STX RAT Targets Finance Sector with Sophisticated Stealth Methods

Meet STX RAT, a sneaky new remote access trojan that's got its sights set on the finance sector, using advanced stealth methods and command-and-control capabilities to evade detection. This latest threat is a wake-up call for defenders, testing their readiness to respond to increasingly sophisticated attacks.

Analyst 207