#remoteaccesstrojan — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #remoteaccesstrojan, aggregated by home.social.
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan. Malicious HTML files
were used to hide and reconstruct the malware payload on the victim
system, allowing attackers to gain remote access, steal sensitive information
and monitor user activities.Pulse ID: 6a80bc3303f9ae43ed5159e7
Pulse Link: https://otx.alienvault.com/pulse/6a80bc3303f9ae43ed5159e7
Pulse Author: cryptocti
Created: 2026-08-15 19:21:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
DCRat Malware Campaign Using HTML Smuggling
A cyber threat campaign was identified where attackers used HTML
Smuggling to deliver DCRat Remote Access Trojan.Pulse ID: 6a80bc8fd397105af7ac4d24
Pulse Link: https://otx.alienvault.com/pulse/6a80bc8fd397105af7ac4d24
Pulse Author: cryptocti
Created: 2026-08-15 19:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocti
-
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr...
Pulse ID: 6a722d8ce0ae0afdde284102
Pulse Link: https://otx.alienvault.com/pulse/6a722d8ce0ae0afdde284102
Pulse Author: AlienVault
Created: 2026-08-04 18:21:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #Discord #ICS #InfoSec #Java #Malware #Mimic #Minecraft #OTX #OpenThreatExchange #PowerShell #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr...
Pulse ID: 6a722d8ce0ae0afdde284102
Pulse Link: https://otx.alienvault.com/pulse/6a722d8ce0ae0afdde284102
Pulse Author: AlienVault
Created: 2026-08-04 18:21:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #Discord #ICS #InfoSec #Java #Malware #Mimic #Minecraft #OTX #OpenThreatExchange #PowerShell #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault
-
MacSync RAT Targets macOS Credentials and Cryptocurrency Wallets
MacSync is a macOS information stealer and a Remote Access Trojan distributed through malicious Google Ads and Claude AI shared conversations. Victims are tricked into executing Terminal commands that deploy malware to steals credentials, cryptocurrency wallets and establish persistent remote access.
Pulse ID: 6a708422cc9833fb7a2ec3f9
Pulse Link: https://otx.alienvault.com/pulse/6a708422cc9833fb7a2ec3f9
Pulse Author: cryptocti
Created: 2026-08-03 12:05:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocurrency #cryptocti
-
MacSync RAT Targets macOS Credentials and Cryptocurrency Wallets
MacSync is a macOS information stealer and a Remote Access Trojan distributed through malicious Google Ads and Claude AI shared conversations. Victims are tricked into executing Terminal commands that deploy malware to steals credentials, cryptocurrency wallets and establish persistent remote access.
Pulse ID: 6a708422cc9833fb7a2ec3f9
Pulse Link: https://otx.alienvault.com/pulse/6a708422cc9833fb7a2ec3f9
Pulse Author: cryptocti
Created: 2026-08-03 12:05:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocurrency #cryptocti
-
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Pulse ID: 6a6ad68f50ddb7ab4a0f10ae
Pulse Link: https://otx.alienvault.com/pulse/6a6ad68f50ddb7ab4a0f10ae
Pulse Author: Tr1sa111
Created: 2026-07-30 04:43:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #bot #Tr1sa111
-
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Pulse ID: 6a6ad68f50ddb7ab4a0f10ae
Pulse Link: https://otx.alienvault.com/pulse/6a6ad68f50ddb7ab4a0f10ae
Pulse Author: Tr1sa111
Created: 2026-07-30 04:43:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #bot #Tr1sa111
-
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identified as DEV#POPPER, which establishes Socket.IO connections for remote control and can execute commands, upload files, read clipboard data, and persist through developer tools. A parallel execution branch downloads additional payloads including an 82 KB Python infostealer assessed to be OmniStealer, targeting browser credentials, Git configurations, and wallet extensions. The compromise affected @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4, with approximately 16,000 weekly downloads. The loader exhibits exact code overlap with the PolinRider family and DEV#POPPER operations.
Pulse ID: 6a696c951815449cad089687
Pulse Link: https://otx.alienvault.com/pulse/6a696c951815449cad089687
Pulse Author: AlienVault
Created: 2026-07-29 02:59:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Clipboard #CyberSecurity #InfoSec #InfoStealer #Java #JavaScript #NPM #Nodejs #OTX #OpenThreatExchange #Python #RAT #RemoteAccessTrojan #Trojan #bot #AlienVault
-
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identified as DEV#POPPER, which establishes Socket.IO connections for remote control and can execute commands, upload files, read clipboard data, and persist through developer tools. A parallel execution branch downloads additional payloads including an 82 KB Python infostealer assessed to be OmniStealer, targeting browser credentials, Git configurations, and wallet extensions. The compromise affected @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4, with approximately 16,000 weekly downloads. The loader exhibits exact code overlap with the PolinRider family and DEV#POPPER operations.
Pulse ID: 6a696c951815449cad089687
Pulse Link: https://otx.alienvault.com/pulse/6a696c951815449cad089687
Pulse Author: AlienVault
Created: 2026-07-29 02:59:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Clipboard #CyberSecurity #InfoSec #InfoStealer #Java #JavaScript #NPM #Nodejs #OTX #OpenThreatExchange #Python #RAT #RemoteAccessTrojan #Trojan #bot #AlienVault
-
Analysis of BlueShell Variants Used by APT Groups
BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities.
Pulse ID: 6a69c06b441d532a963887ee
Pulse Link: https://otx.alienvault.com/pulse/6a69c06b441d532a963887ee
Pulse Author: AlienVault
Created: 2026-07-29 08:57:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chinese #CyberSecurity #InfoSec #Japan #Korea #Linux #Malware #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteAccessTrojan #SouthKorea #Thailand #Trojan #bot #socks5 #AlienVault
-
Analysis of BlueShell Variants Used by APT Groups
BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities.
Pulse ID: 6a69c06b441d532a963887ee
Pulse Link: https://otx.alienvault.com/pulse/6a69c06b441d532a963887ee
Pulse Author: AlienVault
Created: 2026-07-29 08:57:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chinese #CyberSecurity #InfoSec #Japan #Korea #Linux #Malware #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteAccessTrojan #SouthKorea #Thailand #Trojan #bot #socks5 #AlienVault
-
ChonkyChicken Steals Browser Credentials and Conducts Victim Surveillance
ChonkyChicken is a modular Windows remote access trojan built for credential theft and long term surveillance. It can hijack active browser sessions and explore internal networks.
Pulse ID: 6a63fbea209182be9a2d07d8
Pulse Link: https://otx.alienvault.com/pulse/6a63fbea209182be9a2d07d8
Pulse Author: cryptocti
Created: 2026-07-24 23:57:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #Windows #bot #cryptocti
-
ChonkyChicken Steals Browser Credentials and Conducts Victim Surveillance
ChonkyChicken is a modular Windows remote access trojan built for credential theft and long term surveillance. It can hijack active browser sessions and explore internal networks.
Pulse ID: 6a63fbea209182be9a2d07d8
Pulse Link: https://otx.alienvault.com/pulse/6a63fbea209182be9a2d07d8
Pulse Author: cryptocti
Created: 2026-07-24 23:57:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #Windows #bot #cryptocti
-
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos discovered msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware group. This sophisticated RAT never directly touches the network, instead controlling command-and-control communications exclusively through Chrome DevTools Protocol (CDP). It manipulates browsers via CDP, performs signaling with Cloudflare Workers, and establishes WebRTC DataChannels using Twilio TURN as a relay. The infection chain begins with downloading an MSI file containing the RAT payload. msaRAT hijacks Chrome or Edge browsers in headless mode, injects JavaScript code, and establishes encrypted C2 communications through WebRTC. This design makes all external communications appear to originate from legitimate browser processes, effectively hiding C2 traffic within normal web activity and evading detection by firewalls and network monitoring tools.
Pulse ID: 6a62019ab2f0f4c8bf6527a0
Pulse Link: https://otx.alienvault.com/pulse/6a62019ab2f0f4c8bf6527a0
Pulse Author: AlienVault
Created: 2026-07-23 11:57:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #Cisco #Cloud #CyberSecurity #Edge #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #RAT #RansomWare #RemoteAccessTrojan #Rust #Talos #Trojan #Troll #bot #AlienVault
-
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos discovered msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware group. This sophisticated RAT never directly touches the network, instead controlling command-and-control communications exclusively through Chrome DevTools Protocol (CDP). It manipulates browsers via CDP, performs signaling with Cloudflare Workers, and establishes WebRTC DataChannels using Twilio TURN as a relay. The infection chain begins with downloading an MSI file containing the RAT payload. msaRAT hijacks Chrome or Edge browsers in headless mode, injects JavaScript code, and establishes encrypted C2 communications through WebRTC. This design makes all external communications appear to originate from legitimate browser processes, effectively hiding C2 traffic within normal web activity and evading detection by firewalls and network monitoring tools.
Pulse ID: 6a62019ab2f0f4c8bf6527a0
Pulse Link: https://otx.alienvault.com/pulse/6a62019ab2f0f4c8bf6527a0
Pulse Author: AlienVault
Created: 2026-07-23 11:57:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #Cisco #Cloud #CyberSecurity #Edge #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #RAT #RansomWare #RemoteAccessTrojan #Rust #Talos #Trojan #Troll #bot #AlienVault
-
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...
Pulse ID: 6a616004250472ee87e19829
Pulse Link: https://otx.alienvault.com/pulse/6a616004250472ee87e19829
Pulse Author: AlienVault
Created: 2026-07-23 00:27:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault
-
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...
Pulse ID: 6a616004250472ee87e19829
Pulse Link: https://otx.alienvault.com/pulse/6a616004250472ee87e19829
Pulse Author: AlienVault
Created: 2026-07-23 00:27:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault
-
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
A newly discovered Windows stealer and remote access trojan called Dolphin X targets over 300 applications including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. The malware collects credentials ranging from browser logins to SSH keys, .env files, and cloud tokens. A distinctive feature called the AI Profiler automatically scores infected victims based on application usage, browsing activity, and installed software, helping attackers identify high-value targets through daily summaries. The malware builder operates through a remote server that compiles agents and offers optional mutation engines to evade detection. Advertised by a vendor using the alias Kontraktnik, Dolphin X poses significant risk to developers and organizations by potentially exposing access to entire production environments through compromised DevOps credentials.
Pulse ID: 6a61203a6b39de0e8d3d7247
Pulse Link: https://otx.alienvault.com/pulse/6a61203a6b39de0e8d3d7247
Pulse Author: AlienVault
Created: 2026-07-22 19:55:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cloud #CyberSecurity #DevOps #InfoSec #Malware #OTX #OpenThreatExchange #Password #RAT #RemoteAccessTrojan #SSH #Trojan #Windows #Word #bot #cryptocurrency #developers #AlienVault
-
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
A newly discovered Windows stealer and remote access trojan called Dolphin X targets over 300 applications including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. The malware collects credentials ranging from browser logins to SSH keys, .env files, and cloud tokens. A distinctive feature called the AI Profiler automatically scores infected victims based on application usage, browsing activity, and installed software, helping attackers identify high-value targets through daily summaries. The malware builder operates through a remote server that compiles agents and offers optional mutation engines to evade detection. Advertised by a vendor using the alias Kontraktnik, Dolphin X poses significant risk to developers and organizations by potentially exposing access to entire production environments through compromised DevOps credentials.
Pulse ID: 6a61203a6b39de0e8d3d7247
Pulse Link: https://otx.alienvault.com/pulse/6a61203a6b39de0e8d3d7247
Pulse Author: AlienVault
Created: 2026-07-22 19:55:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cloud #CyberSecurity #DevOps #InfoSec #Malware #OTX #OpenThreatExchange #Password #RAT #RemoteAccessTrojan #SSH #Trojan #Windows #Word #bot #cryptocurrency #developers #AlienVault
-
Rust Based Remote Access Trojan Masquerading as NVIDIA Software
Pulse ID: 6a5e11b7a9e3e87231b4b602
Pulse Link: https://otx.alienvault.com/pulse/6a5e11b7a9e3e87231b4b602
Pulse Author: cryptocti
Created: 2026-07-20 12:16:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Rust #Trojan #bot #cryptocti
-
Rust Based Remote Access Trojan Masquerading as NVIDIA Software
Pulse ID: 6a5e11b7a9e3e87231b4b602
Pulse Link: https://otx.alienvault.com/pulse/6a5e11b7a9e3e87231b4b602
Pulse Author: cryptocti
Created: 2026-07-20 12:16:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Rust #Trojan #bot #cryptocti
-
Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.
Pulse ID: 6a5dec09c0c4b7d2a00d7b2c
Pulse Link: https://otx.alienvault.com/pulse/6a5dec09c0c4b7d2a00d7b2c
Pulse Author: AlienVault
Created: 2026-07-20 09:36:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AsyncRAT #CyberSecurity #EDR #Email #FormBook #Government #Healthcare #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #Remcos #RemoteAccessTrojan #Tesla #Trojan #Worm #XLoader #XWorm #bot #AlienVault
-
Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.
Pulse ID: 6a5dec09c0c4b7d2a00d7b2c
Pulse Link: https://otx.alienvault.com/pulse/6a5dec09c0c4b7d2a00d7b2c
Pulse Author: AlienVault
Created: 2026-07-20 09:36:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AsyncRAT #CyberSecurity #EDR #Email #FormBook #Government #Healthcare #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #Remcos #RemoteAccessTrojan #Tesla #Trojan #Worm #XLoader #XWorm #bot #AlienVault
-
GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data
"A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.
Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
Pulse Link: https://otx.alienvault.com/pulse/6a5cbd8f107f8c3b9ebaf4d3
Pulse Author: cryptocti
Created: 2026-07-19 12:05:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti
-
GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data
"A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.
Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
Pulse Link: https://otx.alienvault.com/pulse/6a5cbd8f107f8c3b9ebaf4d3
Pulse Author: cryptocti
Created: 2026-07-19 12:05:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
ESET Exposes BTMOB Android Malware Service
Meet BTMOB, a sneaky Android malware that's being sold as a subscription service - think $700/month or a one-time $5,000 fee for a lifetime license - making it easy for anyone to become a cyber threat actor. This malware-as-a-service platform even comes with a user-friendly APK builder, requiring zero coding skills.
#AndroidMalware #Malwareasaservice #RemoteAccessTrojan #Maas #Rat
-
Lazarus Group Deploys Memory-Only RAT in Financial Sector Attacks
The notorious Lazarus Group has unleashed a sneaky new attack tool, a memory-only Remote Access Trojan (RAT), targeting the financial sector with cunning precision. This stealthy malware, known as RemotePE, is just the latest weapon in the group's arsenal, and it's being used to infiltrate and manipulate its victims.
#LazarusGroup #RemoteAccessTrojan #Rat #FinancialSector #DecentralizedFinance
-
Iran-nexus APT Expands Espionage Ops with New RAT Variants
Unit 42 researchers have uncovered a sophisticated espionage campaign by an Iran-linked threat group, dubbed Screening Serpens, which has deployed six new remote access Trojan (RAT) variants to target entities across the US, Israel, and the Middle East. These variants, part of two distinct malware families, signal a significant…
#IrannexusApt #RemoteAccessTrojan #ScreeningSerpens #EmergingThreats #NationState
-
Ivanti, Palo Alto Networks Flaws Exploited in Active Attacks
Meet Quasar Linux RAT, a sneaky malware that combines remote access, evasion, and data theft capabilities, making it a potent threat to Linux systems. This powerful tool lets hackers secretly control infected hosts, harvest sensitive info, and even create a network of compromised devices that communicate with each other.
#LinuxMalware #QuasarLinuxRat #RemoteAccessTrojan #KernelRootkit #EmergingThreats
-
Obsidian plugin was abused to deploy a remote access trojan
https://cyber.netsecops.io/articles/obsidian-plugin-abused-in-campaign-to-deploy-phantom-pulse-rat/
#HackerNews #ObsidianPlugin #RemoteAccessTrojan #CyberSecurity #ThreatAlert #Malware
-
Obsidian plugin was abused to deploy a remote access trojan
https://cyber.netsecops.io/articles/obsidian-plugin-abused-in-campaign-to-deploy-phantom-pulse-rat/
#HackerNews #ObsidianPlugin #RemoteAccessTrojan #CyberSecurity #ThreatAlert #Malware
-
Python Backdoor Exploits Tunneling Service to Harvest Browser, Cloud Credentials
Meet DEEP#DOOR, a sneaky Python-based backdoor framework that's harvesting browser and cloud credentials by exploiting a tunneling service, and learn how it infiltrates systems through a clever sequence of stealthy steps. This sophisticated threat starts with a simple batch script that disables Windows security…
#PythonBackdoor #Deepdoor #RemoteAccessTrojan #Rat #CredentialHarvesting
-
Obsidian Plugin Abuse Enables PHANTOMPULSE RAT in Finance, Crypto Attacks
Beware of the notebook that's supposed to keep your secrets safe - researchers have discovered a sneaky new attack that uses Obsidian plugin abuse to slip a powerful Trojan into your system. This novel social engineering campaign targets finance and crypto sectors with a previously unknown RAT called PHANTOMPULSE.
#RemoteAccessTrojan #Phantompulse #ObsidianPluginAbuse #Ref6598 #Finance
-
Mirax RAT Exploits Meta Apps to Infiltrate Android Devices
Beware of fake ads on Meta apps - a sneaky new malware called Mirax RAT is using them to secretly take control of Android devices, with a focus on Spanish-speaking nations. This remote access Trojan is part of a growing Malware-as-a-Service economy that's putting unsuspecting users at risk.
#MiraxRat #Malwareasaservice #MetaApps #AndroidMalware #RemoteAccessTrojan
-
Mirax RAT Exploits Meta Ads to Hijack 220,000 Devices
Meet Mirax RAT, a sneaky Android malware that's hijacked over 220,000 devices by exploiting Meta Ads, giving strangers full control over unsuspecting users' phones. This malicious code has rapidly spread to hundreds of thousands of social accounts, showcasing the alarming power of mainstream ad platforms in the wrong hands.
#MiraxRat #AndroidMalware #RemoteAccessTrojan #SocialEngineering #MetaAds
-
New Trojan STX RAT Targets Finance Sector with Sophisticated Stealth Methods
Meet STX RAT, a sneaky new remote access trojan that's got its sights set on the finance sector, using advanced stealth methods and command-and-control capabilities to evade detection. This latest threat is a wake-up call for defenders, testing their readiness to respond to increasingly sophisticated attacks.
#RemoteAccessTrojan #StxRat #FinanceSector #EmergingThreats #AdvancedPersistentThreat
-
Re: Axios remote access trojan (RAT)
https://github.com/axios/axios/issues/10636Luckily I don't use npm much (only #Indiekit) and it wasn't the malicious v1.14.1 or v0.30.4, it was v1.13.2.
Check with `npm list axios` in your /node_modules folder. I also ran `find ~ -type d -path "*/node_modules/plain-crypto-js" 2>/dev/null` to see if the RAT is found any where on my Mac. 🤞Luckily nothing. Scary! Read the full post mortem report above!
-
Re: Axios remote access trojan (RAT)
https://github.com/axios/axios/issues/10636Luckily I don't use npm much (only #Indiekit) and it wasn't the malicious v1.14.1 or v0.30.4, it was v1.13.2.
Check with `npm list axios` in your /node_modules folder. I also ran `find ~ -type d -path "*/node_modules/plain-crypto-js" 2>/dev/null` to see if the RAT is found any where on my Mac. 🤞Luckily nothing. Scary! Read the full post mortem report above!
-
#Axios is the most popular JavaScript HTTP client library with over 100 million weekly downloads. On March 30, 2026, StepSecurity identified two malicious versions of the widely used axios HTTP client library published to npm: [email protected] and [email protected]. The malicious versions inject a new dependency, [email protected], which is never imported anywhere in the axios source code. Its sole purpose is to execute a postinstall script that acts as a cross platform remote access trojan (RAT) dropper, targeting macOS, Windows, and Linux… #Malware #Trojan #RemoteAccessTrojan
-
#Axios is the most popular JavaScript HTTP client library with over 100 million weekly downloads. On March 30, 2026, StepSecurity identified two malicious versions of the widely used axios HTTP client library published to npm: [email protected] and [email protected]. The malicious versions inject a new dependency, [email protected], which is never imported anywhere in the axios source code. Its sole purpose is to execute a postinstall script that acts as a cross platform remote access trojan (RAT) dropper, targeting macOS, Windows, and Linux… #Malware #Trojan #RemoteAccessTrojan
-
Axios Compromised on NPM – Malicious Versions Drop Remote Access Trojan
#HackerNews #Axios #Compromised #NPM #MaliciousVersions #RemoteAccessTrojan #CyberSecurity
-
Axios Compromised on NPM – Malicious Versions Drop Remote Access Trojan
#HackerNews #Axios #Compromised #NPM #MaliciousVersions #RemoteAccessTrojan #CyberSecurity
-
Fake Booking.com emails and BSODs used to infect hospitality staff https://www.helpnetsecurity.com/2026/01/07/fake-booking-com-emails-bsod-hospitality/ #hospitalityindustry #remoteaccesstrojan #socialengineering #Don'tmiss #Securonix #Hotstuff #phishing #malware #Europe #News
-
Fake Booking.com emails and BSODs used to infect hospitality staff https://www.helpnetsecurity.com/2026/01/07/fake-booking-com-emails-bsod-hospitality/ #hospitalityindustry #remoteaccesstrojan #socialengineering #Don'tmiss #Securonix #Hotstuff #phishing #malware #Europe #News
-
A domain registration is more like a lease rather than a deed. You get the exclusive right to use a domain name for a fixed term, but if you miss renewal, someone else can swoop in. What's scary is that with dropcatch services, cybercriminals can automate monitoring of pending‑delete domains and fire off registrations the split‑second a name is deleted by the registry and becomes available again. Think hawks circling for high‑value prey. 🦅
That's what happened to fita[.]org, a popular website owned by the Federation of International Trade Associations (FITA) and referenced by many government bodies including the International Trade Administration (trade.gov). The domain now sits behind Cloudflare and functions as a command-and-control (C2) for the AsyncRAT malware. The actor controlling it also stood up these C2 endpoints:
90phutif[.]cc,90phutis[.]cc,90phutiv[.]cc,90phuttn[.]cc,xoilaclinkf[.]cc,xoilactivi[.]uk,xoilactivik[.]cc,xoilactivil[.]cc,xoilactivim[.]cc,xoilactivin[.]cc,xoilactivio[.]cc,xoilactivip[.]cc,xoilactiviq[.]cc,xoilactivir[.]cc,xoilactivis[.]cc,xoilactivit[.]cc,xoilactiviu[.]cc,xoilactiviv[.]cc,xoilactiviw[.]cc,xoilactivix[.]cc,xoilactiviy[.]cc,xoilactiviz[.]cc,xoilacvnnc[.]tv,xoilacvnnf[.]tv,xoilacvzb[.]cc,xoilacvzc[.]cc,xoilacvze[.]cc,xoilacvzi[.]cc,xoilacvzk[.]cc,xoilacvzn[.]cc,xoilacvzp[.]cc,xoilacvzq[.]cc,xoilacvzz[.]cc,xoilacyys[.]cc,xoilaczc[.]mobi,xoilaczzbb[.]cc,xoilaczzczz[.]tv,xoilaczzdd[.]cc,xoilaczzdzz[.]tv,xoilaczziz[.]tv,xoilaczzszz[.]tv,xoilaczzvzz[.]tv
So make sure to set auto pay for any valuable domains you possess 💳 otherwise you could risk losing them. Proactive IT governance is also part of security.
#InfobloxThreatIntel #dns #async #threatintel #threatintelligence #infosec #cybersecurity #cybercrime #infoblox #rat #asyncrat #malware #dropcatch #domain #cloudflare #remoteaccesstrojan #infostealer #c2
-
A domain registration is more like a lease rather than a deed. You get the exclusive right to use a domain name for a fixed term, but if you miss renewal, someone else can swoop in. What's scary is that with dropcatch services, cybercriminals can automate monitoring of pending‑delete domains and fire off registrations the split‑second a name is deleted by the registry and becomes available again. Think hawks circling for high‑value prey. 🦅
That's what happened to fita[.]org, a popular website owned by the Federation of International Trade Associations (FITA) and referenced by many government bodies including the International Trade Administration (trade.gov). The domain now sits behind Cloudflare and functions as a command-and-control (C2) for the AsyncRAT malware. The actor controlling it also stood up these C2 endpoints:
90phutif[.]cc,90phutis[.]cc,90phutiv[.]cc,90phuttn[.]cc,xoilaclinkf[.]cc,xoilactivi[.]uk,xoilactivik[.]cc,xoilactivil[.]cc,xoilactivim[.]cc,xoilactivin[.]cc,xoilactivio[.]cc,xoilactivip[.]cc,xoilactiviq[.]cc,xoilactivir[.]cc,xoilactivis[.]cc,xoilactivit[.]cc,xoilactiviu[.]cc,xoilactiviv[.]cc,xoilactiviw[.]cc,xoilactivix[.]cc,xoilactiviy[.]cc,xoilactiviz[.]cc,xoilacvnnc[.]tv,xoilacvnnf[.]tv,xoilacvzb[.]cc,xoilacvzc[.]cc,xoilacvze[.]cc,xoilacvzi[.]cc,xoilacvzk[.]cc,xoilacvzn[.]cc,xoilacvzp[.]cc,xoilacvzq[.]cc,xoilacvzz[.]cc,xoilacyys[.]cc,xoilaczc[.]mobi,xoilaczzbb[.]cc,xoilaczzczz[.]tv,xoilaczzdd[.]cc,xoilaczzdzz[.]tv,xoilaczziz[.]tv,xoilaczzszz[.]tv,xoilaczzvzz[.]tv
So make sure to set auto pay for any valuable domains you possess 💳 otherwise you could risk losing them. Proactive IT governance is also part of security.
#InfobloxThreatIntel #dns #async #threatintel #threatintelligence #infosec #cybersecurity #cybercrime #infoblox #rat #asyncrat #malware #dropcatch #domain #cloudflare #remoteaccesstrojan #infostealer #c2
-
Operation Endgame disrupts Rhadamanthys information-stealing malware https://www.bitdefender.com/en-us/blog/hotforsecurity/operation-endgame-disrupts-rhadamanthys-information-stealing-malware #remoteaccessTrojan #Guestblog #Lawℴ #Malware #Europol #botnet
-
🔒 New Android malware called #HyperRat is being sold as a ready-made service, giving attackers remote access, data theft tools and phishing capabilities in one kit.
Read: https://hackread.com/hyperrat-android-malware-sold-spy-tool/
-
How Lazarus Group used fake job ads to spy on Europe’s drone and defense sector https://www.helpnetsecurity.com/2025/10/23/eset-lazarus-operation-dreamjob/ #remoteaccesstrojan #cybersecurity #cybercrime #NorthKorea #Don'tmiss #malware #threats #trojan #scams #News #ESET
-
New Polymorphic Malware Undetected by Security Tools https://thecyberexpress.com/polymorphic-malware-undetected-by-security/ #TheCyberExpressNews #polymorphicmalware #remoteaccesstrojan #ThreatIntelligence #screenrecordings #TheCyberExpress #FirewallDaily #Pythonmalware #cryptomining #CyberThreats #CyberNews #keylogger #malware #XWorm
-
AsyncRAT evolves as ESET tracks its most popular malware forks https://www.helpnetsecurity.com/2025/07/15/asyncrat-forks-eset-research/ #remoteaccesstrojan #cybersecurity #cybercrime #Don'tmiss #keylogger #research #malware #trojan #News #ESET
-
Scattered Spider Targets Aflac, Other Insurance Companies – Source: securityboulevard.com https://ciso2ciso.com/scattered-spider-targets-aflac-other-insurance-companies-source-securityboulevard-com/ #SecurityBoulevard(Original) #rssfeedpostgeneratorecho #RemoteAccessTrojan(RAT) #ThreatIntelligence #CyberSecurityNews #IndustrySpotlight #Insuranceindustry #SecurityAwareness #SecurityBoulevard #socialengineering #Identity&Access #NetworkSecurity #ScatteredSpider #MobileSecurity #SocialFacebook
-
Mei 2025 | Cyberaanvallen, datalekken en ransomware: Hoe Nederland en België zich wapenen tegen de digitale dreiging
Artikel Cybercrimeinfo: https://www.ccinfo.nl/menu-nieuws-trends/actuele-cyberaanvallen/2542185_mei-2025-cyberaanvallen-datalekken-en-ransomware-hoe-nederland-en-belgie-zich-wapenen-tegen-de-digitale-dreiging
Podcast Spotify: https://open.spotify.com/episode/5OajEVmOdBd2SvOmkQNSBQ?si=7d461e1b54a94d5d
Podcast Youtube: https://youtu.be/Ap2SHxxtfQo?si=YakXXHtIkmrNGhND
#Cyberaanvallen #Datalekken #Ransomware #Cybersecurity #Nederland #België #DigitaleDreiging #Cybercrime #Veiligheid #DataPrivacy #Cyberweerbaarheid #Phishing #Malware #RemoteAccessTrojan #VPNKwetsbaarheid