CornFlake RAT
Go-based remote access trojan delivered via fake updates in the CaptiveCrunch campaign. It captures screenshots, steals credentials, and provides remote shell access.
Go-based remote access trojan delivered via fake updates in the CaptiveCrunch campaign. It captures screenshots, steals credentials, and provides remote shell access.
Microsoft has disclosed a cyber espionage campaign, tracked as CaptiveCrunch, that abuses hijacked hotel Wi-Fi captive portals to deliver a remote access…
Pandora RC is a remote access tool used by the attackers to establish remote access to victim machines. It is a legitimate…
SpyNote is a known remote access trojan (RAT) that provides Accessibility Service access, allowing fraudsters to silently sideload and activate the WindRelay…
DEV#POOPER is a malware family that delivers remote access trojans (RATs) via compromised npm packages, often using blockchain-based command-and-control infrastructure.
clientCode is a heavily obfuscated Node.js remote access trojan (RAT) that uploads files, retrieves JavaScript, collects host details, and reads clipboard data,…
zgRAT is a remote access trojan that has been delivered through Cruciferra campaigns targeting the hospitality and travel industries with themes related…
Remote access trojans are part of the malware payloads in Operation Muck and Load, a campaign that abuses GitHub repositories to deliver…
A malware operator left its delivery server exposed, allowing Rapid7 to recover a full toolkit of 1,048 files including lure templates, filename-spoofing…
A malware campaign using WebDAV shares to deliver infostealers and RATs, leveraging AI-assisted tooling and multiple CVEs.