Spark RAT: Open-Source Go-Based RAT Used in Cambodia Campaign
Spark RAT is an open-source, Go-based cross-platform remote access trojan that enables remote control of compromised devices. It is delivered via a…
Spark RAT is an open-source, Go-based cross-platform remote access trojan that enables remote control of compromised devices. It is delivered via a…
PINHOLE is an advanced remote access trojan that abuses FTP banners and uses high-reputation platforms like Pinterest and SurveyMonkey as dead drop…
E4del is a Node.js-based remote access trojan delivered via FTP banner dead drop resolvers. It is embedded in a digitally signed Electron…
SynkLoader is a Python-based loader distributed through Microsoft Teams phishing, presenting as a PowerShell Cleaner. It installs multiple modules including a fake…
CornFlake RAT is a Go-based remote access trojan deployed via adversary-in-the-middle (AitM) attacks, often disguised as browser or OS updates. It performs…
NodeEdgeRAT is a JavaScript-based remote access tool that ships its entire functionality—command execution, file management, and file transfer—in a single script. It…
SpiceRAT is a remote access tool attributed to the Chinese-speaking threat actor SneakyChef. An updated version is equipped to download and run…
Deed RAT is a remote access tool that serves as the predecessor to BLOODALCHEMY. It is part of the malware lineage that…
DriveSilkRAT is a newly discovered remote access tool written in .NET/C++ that uses Google Drive as its command-and-control channel. It supports 12…
CookiETagRAT is a C++-based remote access tool that uses HTTP Cookie and ETag response headers as its command-and-control mechanism to receive and…