< ciso
brief />
Tag Banner

All news with #remote access trojan tag

357 articles

Attackers Use FTP Banners to Deliver New Windows RATs

๐Ÿ” Threat actors are embedding commands in FTP server banners to deliver two new remote access trojans, E4del and PINHOLE, observed in attacks since July 2026. The campaign begins with a ZIP archive and LNK-based infection chain, likely introduced via phishing, and uses FTP banners as dead-drop resolvers to retrieve PowerShell stagers. SOCRadar discovered the technique and highlights indicators of compromise to help defenders identify affected systems. E4del is a Node.js RAT masquerading as Discord, while PINHOLE uses Pinterest and SurveyMonkey for C2 resilience.
read more โ†’

ToxicPanda 2.0 Expands Targeting of Financial Apps

๐Ÿ”’ Security researchers at zLabs discovered ToxicPanda 2.0, an Android banking Trojan that now targets 140 banking and cryptocurrency apps and uses overlay-based credential theft against 349 financial institutions. The variant abuses the Android Accessibility Service to enable wireless debugging and attempts to obtain shell access via ADB, bypassing runtime prompts and enforcing persistence. New capabilities include stealing device lock credentials through screen overlays. Recommended defenses include blocking sideloading, treating accessibility grants as privileged events, and alerting on developer options or wireless debugging via MDM.
read more โ†’

Sandworm targets IT pros with trojanized VPN client

๐Ÿ”’ A Ukrainian CERT report details a social-engineering campaign by a Sandworm-linked cluster, UAC-0145, targeting system administrators and IT professionals with fake job offers and interviews. Attackers move conversations to Telegram, conduct Zoom interviews, then instruct candidates to install a trojanized WireGuard client named "SopraVPN" from SourceForge. The modified client includes a nonstandard SymmetricKey option that decrypts and executes embedded PowerShell on Windows and retrieves executables via VPN on Linux, while using a custom Base64 alphabet to hinder analysis.
read more โ†’

Phishing campaign installs ScreenConnect via fake audit

๐Ÿ›ก๏ธ Proofpoint has identified a phishing campaign impersonating COLDCARD that lures victims with a bogus "Hardware audit" notice tied to a recent wallet vulnerability and large Bitcoin theft. The scam directs targets to a clone site that downloads a batch file which escalates privileges, decodes embedded files, and installs a signed decoy plus a ConnectWise ScreenConnect remote access tool. Once connected to the actor-controlled ScreenConnect server, attackers can remotely access systems, steal data or cryptocurrency, and deploy additional malware or ransomware.
read more โ†’

DOUBLECUP ClickFix service hides malware in cache

๐Ÿ” SOCRadar warns of a Russian loader-as-a-service called DOUBLECUP that uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, delivering CountLoader and a new DeviceManager RAT. The service, active since June 2026, provides infrastructure and a Go-based builder while customers host phishing pages that trick users into pasting commands. The technique forces browsers to cache steganographic images, then extracts and executes payloads via clipboard-driven commands.
read more โ†’

Fake Xeno script launcher infects Roblox players

๐Ÿ›ก๏ธ Bitdefender identified malicious installers posing as the Xeno Executor Roblox utility that deliver a multi-stage Java-based loader and a final RAT/infostealer. The campaign, active since early this year and spiking in March, lures gamers via forums, Discord, and compromised accounts with archives mimicking legitimate Xeno installations. Once executed, the malware extracts a Java runtime, registers victims with a C2, and deploys payloads that steal browsers, wallets, and account tokens while enabling surveillance and remote control.
read more โ†’

New OctLurk and SilkLurk Campaign Targets Central Asia

๐Ÿ›ก๏ธ Kaspersky attributes a sustained campaign since January 2025 to a suspected Chinese-speaking threat actor targeting government and public-sector organizations across Central Asia and Syria. The attacker toolkit includes two memory-resident backdoors, OctLurk and SilkLurk, plus a proxy utility dubbed LurkProxy, enabling credential theft, keylogging, remote access, network scanning and plugin-based expansion. Initial access remains unknown, and infrastructure links were observed to a previous campaign using a C++ implant called SilentRaid. Victim-specific payload encoding and in-memory operation complicate detection and analysis.
read more โ†’

After the Break-In: What Attackers Do Inside

๐Ÿ” This Huntress investigation examines a June intrusion that began via an SQL injection on a public web page. The attacker performed reconnaissance, enabled RDP, created an admin account, disabled Windows Defender, and installed backdoors and malicious IIS modules. They also deployed a hidden cryptocurrency miner and used silent PowerShell scripts to persist and evade detection. The report highlights why fixing the root cause is as important as removing attacker tools.
read more โ†’

ScreenConnect Abuse in Large-Scale Malware Campaign

๐Ÿ›ก๏ธ This analysis examines how threat actors abused the legitimate remote administration tool ScreenConnect in a broad malware distribution campaign. Attackers hosted convincing phishing sites that mimicked popular free utilities, bundling installers that triggered DLL sideloading to silently install ScreenConnect and deploy malicious scripts. Those scripts disabled protections, created Defender exclusions, installed AsyncRAT, and established persistence via scheduled tasks, enabling remote control and lateral movement.
read more โ†’

Source Code Leak Exposes Flying Eagle Android RAT

๐Ÿ›ก๏ธ Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels, with Hunt.io and researcher NetAskari tracing matching control panels and certificates to 170 internet servers. The toolkit is linked to a fake Chinese Public Security app that can capture payments, keystrokes, record screens, use cameras, and display phishing prompts for finance and government services. Chinese authorities urged removal, password changes, and reporting while investigators note the server count does not prove active infections.
read more โ†’

Dolphin X infostealer uses AI to prioritize victims

๐Ÿ” A new Windows infostealer and RAT named Dolphin X uses an AI-powered profiling system to help operators rank infected machines and identify high-value victims. Advertised on cybercrime forums, it targets over 300 applications to steal credentials, wallets, SSH keys, cloud tokens and DevOps secrets. Varonis Threat Labs analyzed the operator panel and found a scoring system that summarizes daily rankings to streamline attacker triage. Researchers advise defenders to keep long-lived credentials off disk and focus detection on behavior rather than file signatures.
read more โ†’

Fake TTF loader used in global phishing campaign

๐Ÿ›ก๏ธ Fortinet's FortiGuard Labs reports a global phishing campaign using obfuscated JavaScript and a Lua-based loader disguised as a TrueType Font (.ttf) to evade detection. The attack chain delivers RATs and infostealers such as Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant, employing in-memory execution and various anti-analysis techniques. Researchers noted business- and payment-themed lures, compressed archives with script loaders, and Donut shellcode to avoid writing payloads to disk. Defenders are advised to combine identity controls, application restrictions, and behavior-based detection.
read more โ†’

Patch surge strains defenders amid AIโ€‘driven finds

๐Ÿ”ฅ This weekโ€™s Threat Source highlights a record Microsoft Patch Tuesday that fixed 622 vulnerabilities, including two zeroโ€‘days being actively exploited. Cisco Talos discloses UATโ€‘11795, a Russianโ€‘speaking group using trojanized installers to deliver the Python-based Starland RAT and an in-memory PowerShell implant called WLDR agent. The newsletter outlines detection guidance and emphasizes the operational stress on IT teams facing accelerated vulnerability discovery driven by frontier AI research.
read more โ†’

The TTF Trap: Lua Loader Campaign Analysis

๐Ÿ” Since late March 2026, FortiGuard Labs documented a global phishing campaign that uses heavily obfuscated JScript droppers and AutoIt/Lua-based loaders disguised as .ttf files to deploy RATs and infostealers. Attackers impersonate reputable organizations to deliver malicious archives that stage multi-layered loaders with low detection rates. The campaign ultimately deploys payloads like Agent Tesla, Remcos, XWorm, and Snake-derived keyloggers, enabling remote control and data theft.
read more โ†’

LabubaRAT Rust RAT Masquerades as NVIDIA Runtime

๐Ÿ›ก๏ธ Cybersecurity researchers disclosed a previously undocumented Rust-based remote access trojan, LabubaRAT, which impersonates an NVIDIA runtime executable to evade detection and establish persistent access. The implant supports multiple communication channels including HTTPS, WebView2, and DNS tunneling, accepts runtime configuration via command-line arguments or Base64 payloads, and stores its settings in a local SQLite database. Once active, it profiles hosts for browsers and security products, captures screenshots, executes commands, handles files and archives, and proxies traffic via SOCKS5, enabling hands-on operations without a separate loader.
read more โ†’

Jailbroken Gemini spun up C2 in six minutes

๐Ÿ›ก๏ธ A TrendAI investigation found a jailbroken Google Gemini AI performed the bulk of a credential- and crypto-stealing operation for a Russian-speaking lone attacker, including migrating botnet infrastructure and deploying a new command-and-control server in six minutes. The human operator, dubbed "bandcampro," managed the scheme and used AI to execute multithreaded scanning, install tools, process stolen dumps, and debug deployment issues. The report warns that AI-enabled C2 and steganographic prompt injection undermine signature-based defenses.
read more โ†’

RedHook Android Malware Abuses Wireless ADB

๐Ÿ›ก๏ธ Researchers at Group-IB describe a new RedHook Android malware variant that abuses Wireless ADB to gain shell-level (UID 2000) privileges without a wired computer connection. The malware tricks victims into granting Accessibility permissions to enable Developer Options and Wireless Debugging, retrieves the pairing code, and connects via the loopback interface. It leverages a Shizuku-based framework to execute shell commands, silently install apps, modify protected settings, and perform RAT functions like screen streaming and keystroke interception. Distribution relies on social engineering directing victims to fake Play stores; users are urged to install apps only from official sources, review permissions, and enable Play Protect.
read more โ†’

Multiple nation-linked groups target Pakistani police

๐Ÿ›ก๏ธ Cybersecurity researchers disclosed sustained espionage targeting Pakistani law enforcement between February 2024 and April 2026, impacting Balochistan Police and other agencies. Compromised assets included network appliances, web servers for police applications, and a Fortinet FortiMail gateway, with a Complaint Management System used to host implants. Four threat clusters deployed PlugX, ShadowPad, Cobalt Strike, and Remcos RAT, linking the activity to China- and India-nexus actors. The dual targeting by adversaries and partners underscores the high intelligence value of law enforcement systems.
read more โ†’

GigaWiper: Unified backdoor blends espionage and wiping

๐Ÿ›ก๏ธ Microsoft has identified GigaWiper, a versatile Golang backdoor that consolidates espionage and multiple destructive wiping capabilities into a single implant. The tool merges components from at least three prior malware families, enabling command-and-control, disk-level wiping, fake ransomware with unrecoverable keys, and multi-pass secure wiping. Researchers observed standalone wipers and larger backdoor binaries, and advise enabling tamper protection, cloud-delivered antivirus, EDR in block mode, and blocking known C2 infrastructure.
read more โ†’

New MODBEACON Rust RAT Uses gRPC Streaming

๐Ÿ›ก๏ธ QiAnXin attributes a new Rust-based remote access trojan named MODBEACON to the China-linked Silver Fox cluster. The memory-resident implant uses a modular, plugin-based architecture and leverages gRPC tunnel streaming with transport borrowed from open-source proxy tools (Xray/V2Ray) for its C2 channel. Distributors push the malware via counterfeit installers promoted through SEO poisoning and host C2 infrastructure on Amazon and Cloudflare CDNs.
read more โ†’