XG-Web: Browser-Centric Remote-Access and Information-Stealing Framework
XG-Web is a browser-centric remote-access and information-stealing framework used by Jewelbug. It turns a victim's browser into a full remote-control channel, allowing…
XG-Web is a browser-centric remote-access and information-stealing framework used by Jewelbug. It turns a victim's browser into a full remote-control channel, allowing…
reverse_ssh is an architecture-specific binary used by the threat actor to establish reverse SSH tunnels for persistent remote access on compromised VMware…
Chrome Remote Desktop is a remote access tool that allows users to control computers remotely. A suspected North Korean operative installed it…
Cybersecurity researchers have uncovered an active, multi-wave campaign that uses social engineering lures themed around Adobe and Zoom updates, business document reviews,…
ScreenConnect, a remote monitoring and management (RMM) tool by ConnectWise, is being abused by threat actors in the SMOKE#SCREEN campaign to gain…
The built-in Take Control feature in N-able N-central was abused by attackers to pivot into managed endpoints after exploiting CVE-2026-18577.
Pandora RC is a remote access tool used by the attackers to establish remote access to victim machines. It is a legitimate…
WAVESHAPER.V2 is a backdoor malware used by UNC1069/Sapphire Sleet, identified in the axios npm compromise. It provides remote access and data exfiltration…
SpyNote is a known remote access trojan (RAT) that provides Accessibility Service access, allowing fraudsters to silently sideload and activate the WindRelay…
Remote access trojans are part of the malware payloads in Operation Muck and Load, a campaign that abuses GitHub repositories to deliver…