home.social

#remoteaccesstrojan — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #remoteaccesstrojan, aggregated by home.social.

fetched live
  1. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  2. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
    were used to hide and reconstruct the malware payload on the victim
    system, allowing attackers to gain remote access, steal sensitive information
    and monitor user activities.

    Pulse ID: 6a80bc3303f9ae43ed5159e7
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:21:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  3. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  4. DCRat Malware Campaign Using HTML Smuggling

    A cyber threat campaign was identified where attackers used HTML
    Smuggling to deliver DCRat Remote Access Trojan.

    Pulse ID: 6a80bc8fd397105af7ac4d24
    Pulse Link: otx.alienvault.com/pulse/6a80b
    Pulse Author: cryptocti
    Created: 2026-08-15 19:22:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti

  5. Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums

    A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr...

    Pulse ID: 6a722d8ce0ae0afdde284102
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: AlienVault
    Created: 2026-08-04 18:21:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CyberSecurity #Discord #ICS #InfoSec #Java #Malware #Mimic #Minecraft #OTX #OpenThreatExchange #PowerShell #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  6. Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums

    A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr...

    Pulse ID: 6a722d8ce0ae0afdde284102
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: AlienVault
    Created: 2026-08-04 18:21:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CyberSecurity #Discord #ICS #InfoSec #Java #Malware #Mimic #Minecraft #OTX #OpenThreatExchange #PowerShell #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  7. MacSync RAT Targets macOS Credentials and Cryptocurrency Wallets

    MacSync is a macOS information stealer and a Remote Access Trojan distributed through malicious Google Ads and Claude AI shared conversations. Victims are tricked into executing Terminal commands that deploy malware to steals credentials, cryptocurrency wallets and establish persistent remote access.

    Pulse ID: 6a708422cc9833fb7a2ec3f9
    Pulse Link: otx.alienvault.com/pulse/6a708
    Pulse Author: cryptocti
    Created: 2026-08-03 12:05:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocurrency #cryptocti

  8. MacSync RAT Targets macOS Credentials and Cryptocurrency Wallets

    MacSync is a macOS information stealer and a Remote Access Trojan distributed through malicious Google Ads and Claude AI shared conversations. Victims are tricked into executing Terminal commands that deploy malware to steals credentials, cryptocurrency wallets and establish persistent remote access.

    Pulse ID: 6a708422cc9833fb7a2ec3f9
    Pulse Link: otx.alienvault.com/pulse/6a708
    Pulse Author: cryptocti
    Created: 2026-08-03 12:05:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocurrency #cryptocti

  9. Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

    Pulse ID: 6a6ad68f50ddb7ab4a0f10ae
    Pulse Link: otx.alienvault.com/pulse/6a6ad
    Pulse Author: Tr1sa111
    Created: 2026-07-30 04:43:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #bot #Tr1sa111

  10. Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

    Pulse ID: 6a6ad68f50ddb7ab4a0f10ae
    Pulse Link: otx.alienvault.com/pulse/6a6ad
    Pulse Author: Tr1sa111
    Created: 2026-07-30 04:43:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #bot #Tr1sa111

  11. Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

    Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identified as DEV#POPPER, which establishes Socket.IO connections for remote control and can execute commands, upload files, read clipboard data, and persist through developer tools. A parallel execution branch downloads additional payloads including an 82 KB Python infostealer assessed to be OmniStealer, targeting browser credentials, Git configurations, and wallet extensions. The compromise affected @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4, with approximately 16,000 weekly downloads. The loader exhibits exact code overlap with the PolinRider family and DEV#POPPER operations.

    Pulse ID: 6a696c951815449cad089687
    Pulse Link: otx.alienvault.com/pulse/6a696
    Pulse Author: AlienVault
    Created: 2026-07-29 02:59:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #Clipboard #CyberSecurity #InfoSec #InfoStealer #Java #JavaScript #NPM #Nodejs #OTX #OpenThreatExchange #Python #RAT #RemoteAccessTrojan #Trojan #bot #AlienVault

  12. Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

    Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identified as DEV#POPPER, which establishes Socket.IO connections for remote control and can execute commands, upload files, read clipboard data, and persist through developer tools. A parallel execution branch downloads additional payloads including an 82 KB Python infostealer assessed to be OmniStealer, targeting browser credentials, Git configurations, and wallet extensions. The compromise affected @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4, with approximately 16,000 weekly downloads. The loader exhibits exact code overlap with the PolinRider family and DEV#POPPER operations.

    Pulse ID: 6a696c951815449cad089687
    Pulse Link: otx.alienvault.com/pulse/6a696
    Pulse Author: AlienVault
    Created: 2026-07-29 02:59:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #Clipboard #CyberSecurity #InfoSec #InfoStealer #Java #JavaScript #NPM #Nodejs #OTX #OpenThreatExchange #Python #RAT #RemoteAccessTrojan #Trojan #bot #AlienVault

  13. Analysis of BlueShell Variants Used by APT Groups

    BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities.

    Pulse ID: 6a69c06b441d532a963887ee
    Pulse Link: otx.alienvault.com/pulse/6a69c
    Pulse Author: AlienVault
    Created: 2026-07-29 08:57:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #InfoSec #Japan #Korea #Linux #Malware #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteAccessTrojan #SouthKorea #Thailand #Trojan #bot #socks5 #AlienVault

  14. Analysis of BlueShell Variants Used by APT Groups

    BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities.

    Pulse ID: 6a69c06b441d532a963887ee
    Pulse Link: otx.alienvault.com/pulse/6a69c
    Pulse Author: AlienVault
    Created: 2026-07-29 08:57:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #InfoSec #Japan #Korea #Linux #Malware #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteAccessTrojan #SouthKorea #Thailand #Trojan #bot #socks5 #AlienVault

  15. ChonkyChicken Steals Browser Credentials and Conducts Victim Surveillance

    ChonkyChicken is a modular Windows remote access trojan built for credential theft and long term surveillance. It can hijack active browser sessions and explore internal networks.

    Pulse ID: 6a63fbea209182be9a2d07d8
    Pulse Link: otx.alienvault.com/pulse/6a63f
    Pulse Author: cryptocti
    Created: 2026-07-24 23:57:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #Windows #bot #cryptocti

  16. ChonkyChicken Steals Browser Credentials and Conducts Victim Surveillance

    ChonkyChicken is a modular Windows remote access trojan built for credential theft and long term surveillance. It can hijack active browser sessions and explore internal networks.

    Pulse ID: 6a63fbea209182be9a2d07d8
    Pulse Link: otx.alienvault.com/pulse/6a63f
    Pulse Author: cryptocti
    Created: 2026-07-24 23:57:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #Windows #bot #cryptocti

  17. Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

    Cisco Talos discovered msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware group. This sophisticated RAT never directly touches the network, instead controlling command-and-control communications exclusively through Chrome DevTools Protocol (CDP). It manipulates browsers via CDP, performs signaling with Cloudflare Workers, and establishes WebRTC DataChannels using Twilio TURN as a relay. The infection chain begins with downloading an MSI file containing the RAT payload. msaRAT hijacks Chrome or Edge browsers in headless mode, injects JavaScript code, and establishes encrypted C2 communications through WebRTC. This design makes all external communications appear to originate from legitimate browser processes, effectively hiding C2 traffic within normal web activity and evading detection by firewalls and network monitoring tools.

    Pulse ID: 6a62019ab2f0f4c8bf6527a0
    Pulse Link: otx.alienvault.com/pulse/6a620
    Pulse Author: AlienVault
    Created: 2026-07-23 11:57:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #Cisco #Cloud #CyberSecurity #Edge #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #RAT #RansomWare #RemoteAccessTrojan #Rust #Talos #Trojan #Troll #bot #AlienVault

  18. Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

    Cisco Talos discovered msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware group. This sophisticated RAT never directly touches the network, instead controlling command-and-control communications exclusively through Chrome DevTools Protocol (CDP). It manipulates browsers via CDP, performs signaling with Cloudflare Workers, and establishes WebRTC DataChannels using Twilio TURN as a relay. The infection chain begins with downloading an MSI file containing the RAT payload. msaRAT hijacks Chrome or Edge browsers in headless mode, injects JavaScript code, and establishes encrypted C2 communications through WebRTC. This design makes all external communications appear to originate from legitimate browser processes, effectively hiding C2 traffic within normal web activity and evading detection by firewalls and network monitoring tools.

    Pulse ID: 6a62019ab2f0f4c8bf6527a0
    Pulse Link: otx.alienvault.com/pulse/6a620
    Pulse Author: AlienVault
    Created: 2026-07-23 11:57:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #Cisco #Cloud #CyberSecurity #Edge #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #RAT #RansomWare #RemoteAccessTrojan #Rust #Talos #Trojan #Troll #bot #AlienVault

  19. Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

    Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...

    Pulse ID: 6a616004250472ee87e19829
    Pulse Link: otx.alienvault.com/pulse/6a616
    Pulse Author: AlienVault
    Created: 2026-07-23 00:27:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault

  20. Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

    Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...

    Pulse ID: 6a616004250472ee87e19829
    Pulse Link: otx.alienvault.com/pulse/6a616
    Pulse Author: AlienVault
    Created: 2026-07-23 00:27:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault

  21. Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI

    A newly discovered Windows stealer and remote access trojan called Dolphin X targets over 300 applications including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. The malware collects credentials ranging from browser logins to SSH keys, .env files, and cloud tokens. A distinctive feature called the AI Profiler automatically scores infected victims based on application usage, browsing activity, and installed software, helping attackers identify high-value targets through daily summaries. The malware builder operates through a remote server that compiles agents and offers optional mutation engines to evade detection. Advertised by a vendor using the alias Kontraktnik, Dolphin X poses significant risk to developers and organizations by potentially exposing access to entire production environments through compromised DevOps credentials.

    Pulse ID: 6a61203a6b39de0e8d3d7247
    Pulse Link: otx.alienvault.com/pulse/6a612
    Pulse Author: AlienVault
    Created: 2026-07-22 19:55:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cloud #CyberSecurity #DevOps #InfoSec #Malware #OTX #OpenThreatExchange #Password #RAT #RemoteAccessTrojan #SSH #Trojan #Windows #Word #bot #cryptocurrency #developers #AlienVault

  22. Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI

    A newly discovered Windows stealer and remote access trojan called Dolphin X targets over 300 applications including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. The malware collects credentials ranging from browser logins to SSH keys, .env files, and cloud tokens. A distinctive feature called the AI Profiler automatically scores infected victims based on application usage, browsing activity, and installed software, helping attackers identify high-value targets through daily summaries. The malware builder operates through a remote server that compiles agents and offers optional mutation engines to evade detection. Advertised by a vendor using the alias Kontraktnik, Dolphin X poses significant risk to developers and organizations by potentially exposing access to entire production environments through compromised DevOps credentials.

    Pulse ID: 6a61203a6b39de0e8d3d7247
    Pulse Link: otx.alienvault.com/pulse/6a612
    Pulse Author: AlienVault
    Created: 2026-07-22 19:55:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cloud #CyberSecurity #DevOps #InfoSec #Malware #OTX #OpenThreatExchange #Password #RAT #RemoteAccessTrojan #SSH #Trojan #Windows #Word #bot #cryptocurrency #developers #AlienVault

  23. Rust Based Remote Access Trojan Masquerading as NVIDIA Software

    Pulse ID: 6a5e11b7a9e3e87231b4b602
    Pulse Link: otx.alienvault.com/pulse/6a5e1
    Pulse Author: cryptocti
    Created: 2026-07-20 12:16:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Rust #Trojan #bot #cryptocti

  24. Rust Based Remote Access Trojan Masquerading as NVIDIA Software

    Pulse ID: 6a5e11b7a9e3e87231b4b602
    Pulse Link: otx.alienvault.com/pulse/6a5e1
    Pulse Author: cryptocti
    Created: 2026-07-20 12:16:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Rust #Trojan #bot #cryptocti

  25. Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service

    Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.

    Pulse ID: 6a5dec09c0c4b7d2a00d7b2c
    Pulse Link: otx.alienvault.com/pulse/6a5de
    Pulse Author: AlienVault
    Created: 2026-07-20 09:36:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #CyberSecurity #EDR #Email #FormBook #Government #Healthcare #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #Remcos #RemoteAccessTrojan #Tesla #Trojan #Worm #XLoader #XWorm #bot #AlienVault

  26. Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service

    Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.

    Pulse ID: 6a5dec09c0c4b7d2a00d7b2c
    Pulse Link: otx.alienvault.com/pulse/6a5de
    Pulse Author: AlienVault
    Created: 2026-07-20 09:36:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #CyberSecurity #EDR #Email #FormBook #Government #Healthcare #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #Remcos #RemoteAccessTrojan #Tesla #Trojan #Worm #XLoader #XWorm #bot #AlienVault

  27. GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data

    "A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.

    Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
    Pulse Link: otx.alienvault.com/pulse/6a5cb
    Pulse Author: cryptocti
    Created: 2026-07-19 12:05:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti

  28. GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data

    "A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.

    Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
    Pulse Link: otx.alienvault.com/pulse/6a5cb
    Pulse Author: cryptocti
    Created: 2026-07-19 12:05:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti

  29. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  30. Contagious Interview malware in SVG images: DPRK campaign

    A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

    Pulse ID: 6a5a8ba0229db5a5b2686baa
    Pulse Link: otx.alienvault.com/pulse/6a5a8
    Pulse Author: AlienVault
    Created: 2026-07-17 20:08:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault

  31. ESET Exposes BTMOB Android Malware Service

    Meet BTMOB, a sneaky Android malware that's being sold as a subscription service - think $700/month or a one-time $5,000 fee for a lifetime license - making it easy for anyone to become a cyber threat actor. This malware-as-a-service platform even comes with a user-friendly APK builder, requiring zero coding skills.

    osintsights.com/eset-exposes-b

    #AndroidMalware #Malwareasaservice #RemoteAccessTrojan #Maas #Rat

  32. Lazarus Group Deploys Memory-Only RAT in Financial Sector Attacks

    The notorious Lazarus Group has unleashed a sneaky new attack tool, a memory-only Remote Access Trojan (RAT), targeting the financial sector with cunning precision. This stealthy malware, known as RemotePE, is just the latest weapon in the group's arsenal, and it's being used to infiltrate and manipulate its victims.

    osintsights.com/lazarus-group-

    #LazarusGroup #RemoteAccessTrojan #Rat #FinancialSector #DecentralizedFinance

  33. Iran-nexus APT Expands Espionage Ops with New RAT Variants

    Unit 42 researchers have uncovered a sophisticated espionage campaign by an Iran-linked threat group, dubbed Screening Serpens, which has deployed six new remote access Trojan (RAT) variants to target entities across the US, Israel, and the Middle East. These variants, part of two distinct malware families, signal a significant…

    osintsights.com/iran-nexus-apt

    #IrannexusApt #RemoteAccessTrojan #ScreeningSerpens #EmergingThreats #NationState

  34. Ivanti, Palo Alto Networks Flaws Exploited in Active Attacks

    Meet Quasar Linux RAT, a sneaky malware that combines remote access, evasion, and data theft capabilities, making it a potent threat to Linux systems. This powerful tool lets hackers secretly control infected hosts, harvest sensitive info, and even create a network of compromised devices that communicate with each other.

    osintsights.com/ivanti-palo-al

    #LinuxMalware #QuasarLinuxRat #RemoteAccessTrojan #KernelRootkit #EmergingThreats

  35. Python Backdoor Exploits Tunneling Service to Harvest Browser, Cloud Credentials

    Meet DEEP#DOOR, a sneaky Python-based backdoor framework that's harvesting browser and cloud credentials by exploiting a tunneling service, and learn how it infiltrates systems through a clever sequence of stealthy steps. This sophisticated threat starts with a simple batch script that disables Windows security…

    osintsights.com/python-backdoo

    #PythonBackdoor #Deepdoor #RemoteAccessTrojan #Rat #CredentialHarvesting

  36. Obsidian Plugin Abuse Enables PHANTOMPULSE RAT in Finance, Crypto Attacks

    Beware of the notebook that's supposed to keep your secrets safe - researchers have discovered a sneaky new attack that uses Obsidian plugin abuse to slip a powerful Trojan into your system. This novel social engineering campaign targets finance and crypto sectors with a previously unknown RAT called PHANTOMPULSE.

    osintsights.com/obsidian-plugi

    #RemoteAccessTrojan #Phantompulse #ObsidianPluginAbuse #Ref6598 #Finance

  37. Mirax RAT Exploits Meta Apps to Infiltrate Android Devices

    Beware of fake ads on Meta apps - a sneaky new malware called Mirax RAT is using them to secretly take control of Android devices, with a focus on Spanish-speaking nations. This remote access Trojan is part of a growing Malware-as-a-Service economy that's putting unsuspecting users at risk.

    osintsights.com/mirax-rat-expl

    #MiraxRat #Malwareasaservice #MetaApps #AndroidMalware #RemoteAccessTrojan

  38. Mirax RAT Exploits Meta Ads to Hijack 220,000 Devices

    Meet Mirax RAT, a sneaky Android malware that's hijacked over 220,000 devices by exploiting Meta Ads, giving strangers full control over unsuspecting users' phones. This malicious code has rapidly spread to hundreds of thousands of social accounts, showcasing the alarming power of mainstream ad platforms in the wrong hands.

    osintsights.com/mirax-rat-expl

    #MiraxRat #AndroidMalware #RemoteAccessTrojan #SocialEngineering #MetaAds

  39. New Trojan STX RAT Targets Finance Sector with Sophisticated Stealth Methods

    Meet STX RAT, a sneaky new remote access trojan that's got its sights set on the finance sector, using advanced stealth methods and command-and-control capabilities to evade detection. This latest threat is a wake-up call for defenders, testing their readiness to respond to increasingly sophisticated attacks.

    osintsights.com/new-trojan-stx

    #RemoteAccessTrojan #StxRat #FinanceSector #EmergingThreats #AdvancedPersistentThreat

  40. Naty S @eclecticpassions ·

    Re: Axios remote access trojan (RAT)

    github.com/axios/axios/issues/

    Luckily I don't use npm much (only ) and it wasn't the malicious v1.14.1 or v0.30.4, it was v1.13.2.

    Check with `npm list axios` in your /node_modules folder. I also ran `find ~ -type d -path "*/node_modules/plain-crypto-js" 2>/dev/null` to see if the RAT is found any where on my Mac. 🤞Luckily nothing. Scary! Read the full post mortem report above!

    @paulrobertlloyd

  41. Re: Axios remote access trojan (RAT)

    github.com/axios/axios/issues/

    Luckily I don't use npm much (only #Indiekit) and it wasn't the malicious v1.14.1 or v0.30.4, it was v1.13.2.

    Check with `npm list axios` in your /node_modules folder. I also ran `find ~ -type d -path "*/node_modules/plain-crypto-js" 2>/dev/null` to see if the RAT is found any where on my Mac. 🤞Luckily nothing. Scary! Read the full post mortem report above!

    @paulrobertlloyd

    #RemoteAccessTrojan #trojan #hack #virus #npm #axios

  42. #Axios is the most popular JavaScript HTTP client library with over 100 million weekly downloads. On March 30, 2026, StepSecurity identified two malicious versions of the widely used axios HTTP client library published to npm: [email protected] and [email protected]. The malicious versions inject a new dependency, [email protected], which is never imported anywhere in the axios source code. Its sole purpose is to execute a postinstall script that acts as a cross platform remote access trojan (RAT) dropper, targeting macOS, Windows, and Linux… #Malware #Trojan #RemoteAccessTrojan

    stepsecurity.io/blog/axios-com

  43. #Axios is the most popular JavaScript HTTP client library with over 100 million weekly downloads. On March 30, 2026, StepSecurity identified two malicious versions of the widely used axios HTTP client library published to npm: [email protected] and [email protected]. The malicious versions inject a new dependency, [email protected], which is never imported anywhere in the axios source code. Its sole purpose is to execute a postinstall script that acts as a cross platform remote access trojan (RAT) dropper, targeting macOS, Windows, and Linux… #Malware #Trojan #RemoteAccessTrojan

    stepsecurity.io/blog/axios-com

  44. A domain registration is more like a lease rather than a deed. You get the exclusive right to use a domain name for a fixed term, but if you miss renewal, someone else can swoop in. What's scary is that with dropcatch services, cybercriminals can automate monitoring of pending‑delete domains and fire off registrations the split‑second a name is deleted by the registry and becomes available again. Think hawks circling for high‑value prey. 🦅

    That's what happened to fita[.]org, a popular website owned by the Federation of International Trade Associations (FITA) and referenced by many government bodies including the International Trade Administration (trade.gov). The domain now sits behind Cloudflare and functions as a command-and-control (C2) for the AsyncRAT malware. The actor controlling it also stood up these C2 endpoints:

    90phutif[.]cc,90phutis[.]cc,90phutiv[.]cc,90phuttn[.]cc,xoilaclinkf[.]cc,xoilactivi[.]uk,xoilactivik[.]cc,xoilactivil[.]cc,xoilactivim[.]cc,xoilactivin[.]cc,xoilactivio[.]cc,xoilactivip[.]cc,xoilactiviq[.]cc,xoilactivir[.]cc,xoilactivis[.]cc,xoilactivit[.]cc,xoilactiviu[.]cc,xoilactiviv[.]cc,xoilactiviw[.]cc,xoilactivix[.]cc,xoilactiviy[.]cc,xoilactiviz[.]cc,xoilacvnnc[.]tv,xoilacvnnf[.]tv,xoilacvzb[.]cc,xoilacvzc[.]cc,xoilacvze[.]cc,xoilacvzi[.]cc,xoilacvzk[.]cc,xoilacvzn[.]cc,xoilacvzp[.]cc,xoilacvzq[.]cc,xoilacvzz[.]cc,xoilacyys[.]cc,xoilaczc[.]mobi,xoilaczzbb[.]cc,xoilaczzczz[.]tv,xoilaczzdd[.]cc,xoilaczzdzz[.]tv,xoilaczziz[.]tv,xoilaczzszz[.]tv,xoilaczzvzz[.]tv

    So make sure to set auto pay for any valuable domains you possess 💳 otherwise you could risk losing them. Proactive IT governance is also part of security.

    #InfobloxThreatIntel #dns #async #threatintel #threatintelligence #infosec #cybersecurity #cybercrime #infoblox #rat #asyncrat #malware #dropcatch #domain #cloudflare #remoteaccesstrojan #infostealer #c2

  45. A domain registration is more like a lease rather than a deed. You get the exclusive right to use a domain name for a fixed term, but if you miss renewal, someone else can swoop in. What's scary is that with dropcatch services, cybercriminals can automate monitoring of pending‑delete domains and fire off registrations the split‑second a name is deleted by the registry and becomes available again. Think hawks circling for high‑value prey. 🦅

    That's what happened to fita[.]org, a popular website owned by the Federation of International Trade Associations (FITA) and referenced by many government bodies including the International Trade Administration (trade.gov). The domain now sits behind Cloudflare and functions as a command-and-control (C2) for the AsyncRAT malware. The actor controlling it also stood up these C2 endpoints:

    90phutif[.]cc,90phutis[.]cc,90phutiv[.]cc,90phuttn[.]cc,xoilaclinkf[.]cc,xoilactivi[.]uk,xoilactivik[.]cc,xoilactivil[.]cc,xoilactivim[.]cc,xoilactivin[.]cc,xoilactivio[.]cc,xoilactivip[.]cc,xoilactiviq[.]cc,xoilactivir[.]cc,xoilactivis[.]cc,xoilactivit[.]cc,xoilactiviu[.]cc,xoilactiviv[.]cc,xoilactiviw[.]cc,xoilactivix[.]cc,xoilactiviy[.]cc,xoilactiviz[.]cc,xoilacvnnc[.]tv,xoilacvnnf[.]tv,xoilacvzb[.]cc,xoilacvzc[.]cc,xoilacvze[.]cc,xoilacvzi[.]cc,xoilacvzk[.]cc,xoilacvzn[.]cc,xoilacvzp[.]cc,xoilacvzq[.]cc,xoilacvzz[.]cc,xoilacyys[.]cc,xoilaczc[.]mobi,xoilaczzbb[.]cc,xoilaczzczz[.]tv,xoilaczzdd[.]cc,xoilaczzdzz[.]tv,xoilaczziz[.]tv,xoilaczzszz[.]tv,xoilaczzvzz[.]tv

    So make sure to set auto pay for any valuable domains you possess 💳 otherwise you could risk losing them. Proactive IT governance is also part of security.

    #InfobloxThreatIntel #dns #async #threatintel #threatintelligence #infosec #cybersecurity #cybercrime #infoblox #rat #asyncrat #malware #dropcatch #domain #cloudflare #remoteaccesstrojan #infostealer #c2

  46. 🔒 New Android malware called #HyperRat is being sold as a ready-made service, giving attackers remote access, data theft tools and phishing capabilities in one kit.

    Read: hackread.com/hyperrat-android-

    #CyberSecurity #Android #Malware #MaaS #RemoteAccessTrojan