Tag: rat
17 articles

Spark RAT Campaign Targets Cambodia, Abuses OPSWAT Driver to Disable Security Tools
A new Spark RAT campaign is targeting Cambodia, using clever tactics like phishing emails and signed DLLs to disable security tools and sneak malicious payloads into victims' systems. The attackers are casting a wide net with diverse lure themes, trying to catch as many unsuspecting victims as possible.

China-linked SilkParasite campaign targets Central Asia with custom RATs
Meet SilkParasite, a sneaky espionage operation linked to China that's been targeting government bodies in Central Asia with a custom arsenal of Remote Access Tools. This sophisticated campaign boasts seven unique RAT families, five of which have never been seen before, and hints at AI-assisted development.

Malware Combo Targets Android Users With Loans, Credit Card Theft
In just 13 minutes, a sophisticated scam combining malware and social engineering tricked Android users into handing over their accounts and credit card info, with the thieves monetizing stolen cards in real time. The attack started with a convincing phone call from someone posing as a bank employee, leading victims to unwittingly download a remote administration tool masquerading as a legitimate app.

WindRelay Malware Enables Live-Call Loan Fraud via NFC Relay Attack
In just 13 minutes, a scammer can use a single phone call to trick victims into installing malware, allowing them to commit card and loan fraud - all thanks to the cunning WindRelay malware. This sneaky software uses NFC relay attacks to enable live-call loan fraud, leaving victims none the wiser.

Malicious npm Packages Deliver Cross-Platform Malware
Nearly 800 malicious npm packages have been discovered delivering a potent cross-platform malware payload, including a remote access trojan and infostealer, via a sneaky trick that tricks developers into loading the malicious code. These packages use cleverly crafted names and README instructions to evade detection and deploy the WEL1DROPPER downloader.

Russian Loader Service Exploits Browser Cache to Deliver Malware
Meet DOUBLECUP, a sneaky Russian loader service that's been hiding in plain sight since June 2026, using browser cache tricks to deliver malware to unsuspecting victims. Its clever ClickFix campaigns conceal malicious code within innocent-looking PNG images, deploying nasty payloads like CountLoader and DeviceManager RAT on Windows and macOS devices.

Malware Campaign Targets Roblox with RAT and Infostealer via Fake Xeno Script Launcher
Roblox players beware: a sneaky malware campaign has been targeting gamers with a fake Xeno Script Launcher, infecting them with a RAT and infostealer since the start of the year. The malware was cleverly spread through gaming forums, Discord, and compromised accounts, masquerading as an "undetected" cheat to evade Roblox's anti-cheat protections.

Dolphin X Stealer Uses AI to Target High-Value Victims
Meet Dolphin X Stealer, a sneaky new Windows malware that's packing some serious AI-powered punch, allowing cybercriminals to zero in on high-value targets with ease. Its operator panel boasts an impressive 329 features, giving attackers an unprecedented level of control and insight.

Windows Stealer Malware Targets 300+ Apps with AI-Powered Profiler
Meet Dolphin X, a sneaky Windows malware that's taking the cybercrime world by storm with its AI-powered profiler and unparalleled ability to infiltrate over 300 apps, swiping sensitive info like browser passwords, crypto wallets, and cloud tokens. This info-stealer is being sold on the dark web as a potent tool for hackers to get their hands on valuable data.

LabubaRAT Exploits NVIDIA Disguise to Control Windows Hosts
Meet LabubaRAT, a sneaky threat that masquerades as NVIDIA software to take control of Windows hosts, allowing hackers to profile, capture, and manipulate sensitive data. Once deployed, it creates a hidden backdoor for further malicious activity.

Ransomware Gang Exploits Microsoft Teams to Conceal Malicious Traffic
Meet Backdoor.Turn, a sneaky new malware that's abusing Microsoft Teams to hide its malicious activities - and it's a game-changer for cyber threats. This clever RAT uses Teams' own infrastructure against us, making it harder to spot its secret communications.

ESET Exposes BTMOB Android Malware Service
Meet BTMOB, a sneaky Android malware that's being sold as a subscription service - think $700/month or a one-time $5,000 fee for a lifetime license - making it easy for anyone to become a cyber threat actor. This malware-as-a-service platform even comes with a user-friendly APK builder, requiring zero coding skills.

Lazarus Group Deploys Memory-Only RAT in Financial Sector Attacks
The notorious Lazarus Group has unleashed a sneaky new attack tool, a memory-only Remote Access Trojan (RAT), targeting the financial sector with cunning precision. This stealthy malware, known as RemotePE, is just the latest weapon in the group's arsenal, and it's being used to infiltrate and manipulate its victims.

CloudZ Malware Exploits Phone Link to Harvest SMS OTPs
Beware of CloudZ malware, a sneaky Windows threat that's been stealing SMS messages and one-time passwords since January 2026 by exploiting Microsoft's Phone Link app. This malicious duo, paired with the Pheno plugin, can capture mobile authentication data without ever touching your smartphone.

CloudZ Malware Exploits Microsoft Phone Link to Harvest SMS and OTPs
Beware: CloudZ malware is exploiting Microsoft's Phone Link feature to intercept SMS and OTPs, putting your sensitive info at risk. This sneaky attack uses a plugin called Pheno to tap into your Phone Link activity and steal your private messages.

Python Backdoor Exploits Tunneling Service to Harvest Browser, Cloud Credentials
Meet DEEP#DOOR, a sneaky Python-based backdoor framework that's harvesting browser and cloud credentials by exploiting a tunneling service, and learn how it infiltrates systems through a clever sequence of stealthy steps. This sophisticated threat starts with a simple batch script that disables Windows security controls and ends with a fully featured Remote Access Trojan (RAT).
New Trojan STX RAT Targets Finance Sector with Sophisticated Stealth Methods
Meet STX RAT, a sneaky new remote access trojan that's got its sights set on the finance sector, using advanced stealth methods and command-and-control capabilities to evade detection. This latest threat is a wake-up call for defenders, testing their readiness to respond to increasingly sophisticated attacks.