NomadRAT: Modular C++ RAT with Plugin Architecture
NomadRAT is a C++-based remote access tool featuring a main orchestrator and a dedicated transmitter library for C2 traffic. It fetches plugins…
NomadRAT is a C++-based remote access tool featuring a main orchestrator and a dedicated transmitter library for C2 traffic. It fetches plugins…
GoginRAT is a Go-based remote access tool with architectural similarities to NomadRAT. It uses a separate transmitter for C2 and implements file…
NanoCore is a remote access trojan that has been identified in malware samples communicating with Sable Squirrel's infrastructure, highlighting its role in…
njRAT is a remote access trojan that has been detected in malware samples communicating with Sable Squirrel's infrastructure, contributing to the threat…
Russian cybersecurity vendor Kaspersky has uncovered a new attack campaign by the threat actor known as Head Mare, targeting unpatched TrueConf videoconferencing…
PhantomCore is a backdoor and remote access trojan (RAT) delivered through poisoned TrueConf client installers. It is part of an attack chain…
A new campaign has been discovered publishing nearly 800 malicious packages to the npm registry, designed to deliver a cross-platform remote access…
A new Russian loader-as-a-service (LaaS) operation named DOUBLECUP is leveraging ClickFix social engineering lures and steganographic PNG images cached in victims' browsers…
DeviceManager is a modular Python-based remote access trojan distributed via DOUBLECUP. It uses EtherHiding to resolve C2 servers via Ethereum/Polygon smart contracts…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack targeting users of Alibaba developer tools with a cross-platform remote access trojan…