< ciso
brief />
Tag Banner

All news with #remote access trojan tag

380 articles

Engineer jailed for locking thousands of employer devices

πŸ”’ A former core infrastructure engineer pleaded guilty after remotely accessing his employer's network and scheduling tasks that changed hundreds of passwords, deleted domain admin accounts, and disabled thousands of servers and workstations. He sent a ransom demand claiming backups were deleted and threatened further shutdowns unless paid 20 bitcoin. The attack occurred in November–December 2023 and led to a 32-month federal prison sentence.
read more β†’

ClingSTUN backdoor exploits unpatched IoT flaws

πŸ” FortiGuard Labs has identified a Linux proxy backdoor named ClingSTUN that leverages unpatched internet-facing IoT vulnerabilities to turn devices into remotely controlled proxy nodes. The malware abuses legitimate public STUN servers to keep NAT bindings open and blend its traffic with normal VoIP/WebRTC communications. Operators deployed the campaign in three waves, expanding exploited vulnerabilities to at least 24 CVEs and adding hard-coded exploits to aid propagation. FortiGuard urges device inventory, prioritised patching and compensating controls where updates are unavailable.
read more β†’

CSuite phishing campaign escalates to account and endpoint access

πŸ” ANY.RUN researchers traced a US-focused CSuite phishing campaign across hundreds of sandbox analyses, finding 51% of submissions from the United States and heavy exposure in technology, manufacturing, government, and consulting. The operation uses business-themed lures (Adobe, DocuSign, Zoom, Microsoft 365) to either harvest credentials or deliver droppers that install legitimate remote-access tools like ScreenConnect and Action1. This dual path enables mailbox takeover, financial fraud, persistent RMM access, and lateral misuse of trusted identities, expanding impact beyond typical phishing.
read more β†’

Phishing abuses RMM tools to secure persistent access

πŸ›‘οΈ Microsoft observed July 2026 phishing campaigns that distributed a masqueraded, digitally signed MSP360 RMM installer via diverse social-engineering lures and hosting services. The installer established persistent MSP360 services after UAC elevation and was used to silently download and install a ConnectWise ScreenConnect client as a secondary remote-access channel. Threat actors then used these legitimate administration platforms to deploy additional tooling for credential access and information collection while blending into normal IT workflows.
read more β†’

Custom ChatGPT variants used to push RAT malware

πŸ”’ Researchers at Huntress found threat actors publishing malicious custom GPTs on OpenAI that steer users to a Google Sites page hosting a fake Cloudflare check and a PowerShell command. If executed, the command installs an MSI that sideloads a modified DLL to deliver a remote access trojan (RAT) with remote desktop, audio/camera capture, reconnaissance and persistence functionality. OpenAI removed one GPT by September 25, but variants persisted; the campaign leverages legitimate ChatGPT hosting to increase credibility and employs an encrypted custom archive to conceal components.
read more β†’

Star Blizzard uses event lures to deploy CosmicPulse backdoor

πŸ›‘οΈ Microsoft says Russian-linked actor Star Blizzard has used fake event invitations and replying email threads to trick targets into running a Windows backdoor installer. Campaigns since January have targeted organizations tied to Ukraine, mainly in the U.S. and U.K., using hacked WordPress and cPanel accounts and a technique called RedFlick to install the CosmicPulse backdoor via scheduled tasks.
read more β†’

Star Blizzard adopts RedFlick to streamline malware delivery

πŸ›‘οΈ Since January 2026, Microsoft observed Russian state-affiliated actor Star Blizzard refine large-scale phishing, use compromised-site accounts, and adopt a novel malware delivery technique called RedFlick. RedFlick leverages scheduled tasks to deploy the actor’s Python backdoor CosmicPulse, reducing required user interaction to a single response and improving evasion. Microsoft details observed TTPs, IOCs, mitigations, and detection guidance to help organizations defend against this evolving threat.
read more β†’

RatHat C2 evolves into malware-as-a-service hub

πŸ” Research shows the RatHat Android banking trojan's backend evolved far more than the implant itself, with successive C2 panels that can build malware, manage infected devices and use AI to prioritize victims. Cleafy observed three panel generations and a rebrand from BlackCat to Panda Workshop between late 2025 and September 2026, with nearly 100 deployments since April 2026. Panels now support operator 2FA, phishing page builders, role-based accounts and the ability to deploy a native Go service for shell-level persistence outside app permissions.
read more β†’

SectopRAT variant hidden in legitimate Windows software

πŸ›‘οΈ The FortiGuard Incident Response team investigated a Windows intrusion where a SectopRAT .NET RAT was concealed inside a legitimate audio application. The malware used a tampered DLL and a multi-stage loader that extracted an encrypted payload from a DB file, initialized the .NET runtime in memory, and executed a heavily obfuscated RAT. The variant communicates over AES-encrypted channels with a hardcoded C2 and backup domains, supports 29 control commands, and steals browser, email, gaming, and cryptocurrency wallet credentials.
read more β†’

ClickFix Lures Deploy ChainScript RAT via Decentralized C2

πŸ›‘οΈ Blackpoint APG researchers detail a campaign using ClickFix-style lures to deliver a new remote access trojan named ChainScript. The RAT, disguised under multiple build names and posing as legitimate apps like Spotify and Microsoft Teams, uses a Polygon smart contract for EtherHiding-style C2 discovery and communicates over WebSockets. ChainScript provides extensive remote capabilities including shell access, file ops, screenshots, wallet enumeration, and self-updating persistence via scheduled tasks and registry fallbacks.
read more β†’

Jade Sleet Compromises Indian IT Firm via DevOps Lure

πŸ›‘οΈ SentinelOne attributes a campaign by the North Korean-linked group Jade Sleet to the compromise of an India-based IT services provider, using macOS backdoors FLATROOF and ROOFDECK. The attackers employed job-interview and coding project lures with weaponized Terraform lock files to trick developers into fetching malicious modules. FLATROOF uses Telegram for C2 and data theft, while ROOFDECK leverages the Nostr protocol for decentralized C2 and persistent, signed command execution. The incident underscores the growing risk to developer endpoints and supply chain vectors.
read more β†’

ThreatsDay: AI Agents, Exposed Services, and Ransomware

πŸ“° This week's ThreatsDay Bulletin tracks diverse attack trends where keys and secrets are repeatedly exposed across AI tools, internet-facing services, old vulnerabilities, and weak credentials. Highlights include a PPI malware marketplace delivering cross-platform RATs, widespread compromise of unauthenticated LocalAI instances, and research showing AI agents can retrain and replace their own models. Additional items cover ransomware exploiting VMware, Oracle's large September patch update, insider SIM-swap convictions, RF side-channel leaks, and resurgence of Cyclops Blink on Cisco FMC.
read more β†’

KREMLIN malware forces browser extension installs

πŸ”’ Researchers at Elastic Security Labs uncovered a banking malware toolkit called KREMLIN that has been active since mid-2025 and installs malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive data. The infection begins with a malicious JavaScript file posing as banking documents, which downloads Node.js, establishes persistence, and retrieves payload locations from an Ethereum smart contract. KREMLIN copies extensions into browser profile directories, regenerates integrity HMACs using browser keys, and enables them without user consent, while also operating as an info-stealer and delivering RATs like REMCOS.
read more β†’

MeshCentral backdoor used in 3BB broadband intrusion

πŸ”Ž Hunt.io discovered an active intrusion in Thailand ISP 3BB where an attacker installed MeshCentral as a hidden backdoor to maintain remote root access. The exposed server captured on June 3, 2026, contained tools, device lists, and scripts targeting RADIUS databases, FortiGate SSL‑VPN appliances, and internal portals. Cleanup scripts removed logs but deliberately left the agent to preserve persistence.
read more β†’

Packed Android RAT with ADB worm spreads via exposed services

πŸ” Dark Atlas researchers detailed a packed Android remote access trojan (RAT) tracked as THost9 that conceals a loader inside an app and loads a second-stage payload, tc9.dex. The loader decodes and decompresses an embedded asset, starts a foreground service, and can enable an accessibility service when permissions allow. The second stage adds shell execution, file transfer, tunneling, reverse shell and downloadable modules, and includes a worm that scans for exposed Android Debug Bridge (ADB) services to propagate. Analysts linked infections to public ADB and Redroid exposures and recommend removing public ADB access and auditing accessibility services and persistent Redroid data.
read more β†’

New 'ted' backdoor hidden in trojanized HAProxy

πŸ›‘οΈ A previously undocumented Linux toolkit named ted was compiled into trojanized HAProxy binaries on two South Korean hosts, intercepting web traffic and serving altered pages to selected visitors. Rapid7 links the implant with medium confidence to North Korean state actors and identifies victims in the automotive and media sectors. The implant uses specially crafted requests to enter C2 mode, erases its activity from HAProxy counters and returns operator responses over ordinary HTTP headers. Rapid7 shared IoCs and recommended network correlation, memory analysis and binary integrity checks.
read more β†’

Russian Extradition in Major Freelance Platform Malware Case

πŸ“° A Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited to the US and appeared in federal court on charges alleging he helped distribute malware to roughly 80,000 users of a freelance employment platform between 2016 and 2017. The indictment accuses him and co-conspirators of using fake messaging accounts to send malicious Excel attachments that installed remote access trojans, harvesting credentials and PII to support fraud. He faces multiple charges including conspiracy, unauthorized access and aggravated identity theft and remains in federal custody pending further proceedings.
read more β†’

Extradited Russian Hacker Charged Over 2016–2017 Campaign

πŸ” The U.S. Department of Justice has charged Searzhudin Tamirlanovich Aktulaev, extradited from Cyprus on August 28, for operating roughly 255 fake accounts on a freelance platform to distribute malware-laced Excel attachments to about 80,000 users in 2016–2017. The indictment, unsealed after his August 31 appearance in San Francisco, alleges use of TVRAT and DarkVNC to gain remote control, steal data, and facilitate fraud. Aktulaev denies the charges; the DoJ notes allegations are unproven until conviction.
read more β†’

Russian Charged for Malware Campaign Targeting Freelancers

πŸ›‘οΈ A U.S. federal grand jury indicted Russian national Searzhudin Aktulaev for a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. Extradited from Cyprus, Aktulaev allegedly used hundreds of fake accounts between 2016 and 2017 to send malicious Excel attachments that deployed remote-access malware to roughly 80,000 targets. The malware exfiltrated credentials and PII to command-and-control servers, many hosted in the U.S., and half of victims were in the United States.
read more β†’

Spring Ring: Voice Phishing Through Collaboration Tools

πŸ›‘οΈ Between January and April 2026, Unit 42 uncovered a coordinated vishing operationβ€”named Spring Ringβ€”using external Microsoft Teams accounts to impersonate IT help desk staff. The attackers contacted over 150 employees across at least 10 companies and employed live voice calls to coerce victims into installing RMM tools or custom malware. Two distinct campaigns were observed: one delivering an obfuscated PowerShell RAT and another using tailored executables that attempted NTLM relay attacks against domain controllers.
read more β†’