Tag: rat
-
Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems
Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware has been active since at least mid-2016 but was long mistaken for variants of Gh0st RAT, Rekoobe, and other…
-
Luciferus Uncensored AI Service Lets Cybercriminals Generate RAT Malware
Cybercriminals are promoting a new “uncensored” artificial intelligence service called Luciferus that allegedly generates malicious code, including components for remote access trojans (RATs), without the safeguards typically found in mainstream AI platforms. Researchers from the Sophos Counter Threat Unit reported that they first noticed a user named “Optimus_Prime” advertising this subscription service on August 24.…
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Artificial intelligence is rapidly changing the way software is developed, analyzed, and secured. However, the same capabilities that help developers inspect applications can also be misused by cybercriminals to automate reconnaissance, identify exposed secrets, and accelerate data theft.According to Cybersecurity… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker/
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Artificial intelligence is rapidly changing the way software is developed, analyzed, and secured. However, the same capabilities that help developers inspect applications can also be misused by cybercriminals to automate reconnaissance, identify exposed secrets, and accelerate data theft.According to Cybersecurity… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker/
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Artificial intelligence is rapidly changing the way software is developed, analyzed, and secured. However, the same capabilities that help developers inspect applications can also be misused by cybercriminals to automate reconnaissance, identify exposed secrets, and accelerate data theft.According to Cybersecurity… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker/
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cybercriminals are increasingly turning trusted online platforms into malware delivery channels. Gaming videos, software tutorials, search results, and file-download pages can all be manipulated to make malicious installers appear legitimate. According to Cybersecurity News, hackers abused YouTube gaming channels and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker-2/
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cybercriminals are increasingly turning trusted online platforms into malware delivery channels. Gaming videos, software tutorials, search results, and file-download pages can all be manipulated to make malicious installers appear legitimate. According to Cybersecurity News, hackers abused YouTube gaming channels and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker-2/
-
Fake GTA6 ‘Leaked Download’ Caught Spreading RATs, Infostealer and Wiper Ransomware
Cybersecurity firm Huntress has uncovered a malware campaign that preys on excitement for Grand Theft Auto VI (GTA6), packaging remote access trojans, an infostealer, and destructive ransomware inside fake >>leaked<< copies of the hotly anticipated game. GTA6 is not due for release for another three months, but a wave of gameplay footage leaks and an…
-
THost9 Android RAT Pairs Packed Loader With ADB Worm
THost9 hides its payload and uses ADB to spread across exposed Android devices and containers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/
-
Fake Minecraft Mod Drops Myth Stealer RAT to Steal Passwords and Remotely Control PCs
A trojanized Minecraft optimization mod posing as a companion to the legitimate Lithium project has been used to deploy Myth Stealer 3.2-FIX, a password-stealing malware family with remote-access, surveillance, persistence, and victim-harassment capabilities. The malicious archive, tracked as MythStealer.jar_, masquerades as Lithium Extras 0.15.0+mc1.21.1 by “soder.” It abuses the reputation of CaffeineMC’s legitimate Lithium performance…
-
New PackClient RAT sold on Telegram
Tags: ratFirst seen on scworld.com Jump to article: www.scworld.com/brief/new-packclient-rat-sold-on-telegram-targets-organizations-in-china-and-india
-
Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies
A sophisticated malware campaign has abused a trojanized installer for the legitimate Exodus cryptocurrency wallet to deploy a modular remote access trojan (RAT) capable of stealing browser credentials, session cookies, and extension data. The campaign prioritizes long-term interactive access over direct cryptocurrency theft, combining hidden VNC, SOCKS proxying, file management and browser-data theft in an…
-
Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs
Iran-linked threat actor Mirage Kitten is targeting software developers with fake recruitment assessments that hide two newly identified cross-platform remote access trojans: NodeRabbit and PollCat. The campaign uses recruiter impersonation on LinkedIn and other job-search platforms, weaponized Node.js projects, and cloud-hosted ZIP archives to gain covert access to developer endpoints across Windows, Linux, and macOS.…
-
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript.Russian cybersecurity company Kaspersky is tracking the First seen…
-
Infostealer Infection Exposes Blind Eagle-Linked Operator’s Malware Production Pipeline
A compromised attacker-side workstation has given researchers an unusual view into the operational ecosystem behind a suspected Blind Eagle malware campaign, exposing RAT builders, phishing templates, bulk-mail tooling, crypter activity and infrastructure tracking records. Rather than directly exposing a modified executable, the account hosted a legitimate AutoIt interpreter alongside separately retrievable malicious script logic an…
-
Go Loader Uses Anti-Sandbox Checks and SNOWLIGHT to Execute Fileless VShell RAT in Memory
A Windows malware campaign disguised as a graduate-school resume has been observed delivering the SNOWLIGHT stager and a fileless VShell remote-access trojan (RAT) to targets likely associated with Chinese academic and technical research environments. The attack uses a custom 32-bit Go loader that performs sandbox checks, opens a legitimate-looking Word document as a decoy, and…
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT.”The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics,”…
-
Core Werewolf Hackers Deploy New CoreRAT Malware Against Russian Government and Defense Organizations
The Core Werewolf espionage cluster has introduced a previously undocumented remote access trojan dubbed CoreRAT in targeted attacks on Russian public-sector bodies and defense-industry organizations. The shift is notable because Core Werewolf, previously associated with the abuse of legitimate UltraVNC remote-access software and smaller custom backdoors, now operates a full-featured C++ RAT of its own.…
-
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the…
-
RAT-Familie Abyssos nutzt wandelnde Verschleierungstechniken
Ende Juni 2026 haben die Sicherheitsforscher des Zscaler-ThreatLabz eine neue Malware-Familie identifiziert, die den Namen Abyssos erhielt. Bei der in C++ geschriebenen Malware handelt es sich um ein modulares Remote-Administration-Tool (RAT). Die Malware besitzt umfangreiche Fähigkeiten für den Diebstahl von Anmeldeinformationen, die Exfiltration von Dateien sowie den direkten Fernzugriff via VNC. Zusätzlich legen die Entwickler…
-
Attackers use FTP banners to hide new E4del and PINHOLE RATs
Tags: ratFirst seen on scworld.com Jump to article: www.scworld.com/brief/attackers-use-ftp-banners-to-hide-new-e4del-and-pinhole-rats
-
SilkParasite Uses Google Drive as C2 to Hide RAT Traffic Inside Trusted Cloud Services
SilkParasite, a long-running cyberespionage operation targeting government bodies across Central Asia through a compact but highly mature arsenal of remote access trojans. Assessed with medium confidence as China-nexus activity, the campaign stands out for using Google Drive as a command-and-control channel, allowing malware traffic to blend into cloud activity that many enterprises inherently trust. The…
-
SilkParasite Threatens Central Asian Orgs With Flurry of RATs
A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China’s APTs. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/silkparasite-central-asian-orgs-flurry-rats
-
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a First seen…
-
Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-harvesting kit. It operates as a subscription-based criminal service that rents access to affiliates, lowering the barrier for telemarketing fraud groups and inexperienced…

