Remote Access Trojan (RAT) Distributed via GitHub Repositories
Remote access trojans are part of the malware payloads in Operation Muck and Load, a campaign that abuses GitHub repositories to deliver…
Remote access trojans are part of the malware payloads in Operation Muck and Load, a campaign that abuses GitHub repositories to deliver…
A malware operator left its delivery server exposed, allowing Rapid7 to recover a full toolkit of 1,048 files including lure templates, filename-spoofing…
A malware campaign using WebDAV shares to deliver infostealers and RATs, leveraging AI-assisted tooling and multiple CVEs.
A modular .NET RAT delivered via DLL sideloading through a signed Ubisoft binary, part of the DlrtyGames campaign.
ViteVenom is a malware campaign discovered by Checkmarx that uses seven malicious scoped npm packages to deliver a RAT via blockchain-based C2…
ChainVeil is a previous malware campaign that used unscoped typosquat npm packages and a four-tier blockchain C2 infrastructure to deliver a remote…
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
Stowaway is a proxy and remote access tool with SOCKS5 proxying, port forwarding, reverse tunneling, remote shell access, file transfer, and SSH-based…
McMx RAT is a basic Go-based proxy and remote access tool that is a lightweight version of GoSerpent. It includes capabilities such…
Cybersecurity researchers at Kaspersky have uncovered a previously undocumented malware called GoSerpent, used since late 2025 in cyber attacks targeting government and…