Tag: remote access trojan (RAT)

Mirax Android RAT Turns Devices into SOCKS5 Proxies Reaching 220,000 via Meta Ads
News

Mirax Android RAT Turns Devices into SOCKS5 Proxies Reaching 220,000 via Meta Ads

Mirax is a new Android remote access trojan that has been seen actively targeting Spanish-speaking nations. Through Meta advertising, campaigns have reached over 220,000 users on Facebook, Instagram, Messenger, and Threads. According to Italian online fraud protection company Cleafy, Mirax incorporates sophisticated Remote Access Trojan (RAT) capabilities, enabling threat actors to completely communicate with compromised devices in real time. By transforming compromised devices into residential proxy nodes, Mirax increases its operational utility beyond conventional RAT behavior. It creates persistent proxy channels that enable attackers to route their traffic through the victim's actual IP address by utilizing Yamux multiplexing and SOCKS5 protocol support. The initial informati...
GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser Crypto Data
News

GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser Crypto Data

A new iteration of the GlassWorm campaign has been identified by cybersecurity researchers. It offers a multi-stage framework that can install a remote access trojan (RAT) that launches an information-stealing Google Chrome extension that poses as an offline version of Google Docs. According to a paper released last week by Aikido security researcher Ilyas Makari, it records keystrokes, dumps cookies and session tokens, takes images, and receives commands from a C2 server concealed in a Solana blockchain document. A persistent effort known as "GlassWorm" gains an initial footing through rogue packages released on GitHub, PyPI, npm, and the Open VSX marketplace. Furthermore, it is known that the operators hack project maintainers' accounts in order to distribute malicious updates. ...
Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials
News

Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials

Researchers studying cybersecurity have found a malicious npm package that poses as an OpenClaw installer in order to install a remote access trojan (RAT) and steal private information from compromised machines. On March 3, 2026, a person going by the moniker "openclaw-ai" uploaded the package, titled ".openclaw-ai/openclawai," to the registry. To date, 178 people have downloaded it. As of this writing, you can still download the library. According to JFrog, which found the program, it is intended to install a persistent RAT with remote access capabilities, SOCKS5 proxy, and live browser session cloning, as well as steal system passwords, browser data, cryptocurrency wallets, SSH keys, Apple Keychain databases, and iMessage histories. According to security researcher Meitar Palas...
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures
News

CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures

Cybersecurity researchers have revealed information about an ongoing campaign known as KongTuke, which used a malicious Google Chrome extension disguising itself as an ad blocker to purposefully crash the web browser and trick victims into executing arbitrary commands using ClickFix-like lures in order to deliver a previously undiscovered remote access trojan (RAT) known as ModeloRAT. Huntress has given this new ClickFix escalation the code name CrashFix. KongTuke is a traffic distribution system (TDS) that is known to profile victim hosts before rerouting them to a payload delivery site that infects their systems. It is also tracked as 404 TDS, Chaya_002, LandUpdate808, and TAG-124. Other threat actors, such as ransomware gangs, are subsequently granted access to these infected si...
Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia
News

Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia

A new wave of attacks against Indian governmental, academic, and strategic organizations using a remote access trojan (RAT) that gives them long-term control over infected hosts has been linked to the threat actor Transparent Tribe. In order to avoid user suspicion, the campaign uses deceptive distribution mechanisms, such as a weaponized Windows shortcut (LNK) file that is embedded with complete PDF content and poses as a valid PDF document, according to a technical assessment from CYFIRMA. The hacking group Transparent Tribe, commonly known as APT36, is well-known for launching cyberespionage operations against Indian businesses. The state-sponsored enemy, thought to be of Indian descent, has been operating since at least 2013. To achieve its objectives, the threat actor has an...
Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain
News

Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain

Researchers in cybersecurity have provided insight on TA585, a hitherto unknown threat actor that has been seen using phishing attempts to distribute the commercial malware MonsterV2. The threat activity cluster, which uses web injections and filtering checks as part of its attack chains, was characterized as sophisticated by the Proofpoint Threat Research Team. According to researchers Kyle Cucci, Tommy Madjar, and Selena Larson, TA585 is noteworthy since it seems to control its whole assault chain with a variety of delivery methods. TA585 handles its own infrastructure, delivery, and malware installation rather than relying on other threat actors to do things like pay for distribution, purchase access from initial access brokers, or use a third-party traffic delivery system. Mo...
AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto
News

AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto

Researchers in cybersecurity have revealed the specifics of a new campaign that uses the legitimate Remote Monitoring and Management (RMM) program ConnectWise ScreenConnect to deliver a fleshless loader that drops the AsyncRAT remote access trojan (RAT) to steal private information from compromised hosts. After gaining remote access via ScreenConnect, the attacker ran a layered PowerShell loader and VBScript script that retrieved and ran obfuscated components from external URLs. According to a source provided to The Hacker News, LevelBlue stated. Among these were encoded.NET assemblies that eventually unpacked into AsyncRAT while retaining persistence through a fictitious scheduled activity called "Skype Updater. According to the cybersecurity company's documentation of the infectio...
PlayPraetor Android Trojan Infects 11000+ Devices via Fake Google Play Pages and Meta Ads
News

PlayPraetor Android Trojan Infects 11000+ Devices via Fake Google Play Pages and Meta Ads

PlayPraetor is a new Android remote access trojan (RAT) that has infected over 11,000 devices, mostly in Portugal, Spain, France, Morocco, Peru, and Hong Kong, according to cybersecurity researchers. According to a study of the malware by Cleafy researchers Simone Mattia, Alessandro Strino, and Federico Valentini, the aggressive campaigns targeting Spanish and French speakers are responsible for the botnet's explosive growth, which now surpasses 2,000 new infections every week. This suggests a strategic departure from the malware's prior common victim base. PlayPraetor, which is controlled by a Chinese command-and-control (C2) panel, differs greatly from other Android trojans in that it can serve phony overlay login screens on top of almost 200 banking apps and cryptocurrency wallet...
New PHP-Based Interlock RAT Variant Uses FileFix Delivery Mechanism to Target Multiple Industries
News

New PHP-Based Interlock RAT Variant Uses FileFix Delivery Mechanism to Target Multiple Industries

As part of an extensive campaign utilizing a ClickFix variant known as FileFix, threat actors behind the Interlock ransomware gang have released a new PHP variant of their custom remote access trojan (RAT). In a technical investigation released today in partnership with Proofpoint, The DFIR Report stated that since May 2025, Interlock RAT activity has been noted in relation to the LandUpdate808 (also known as KongTuke) web-inject threat clusters. The campaign starts with hijacked websites that, frequently without the owners' or visitors' knowledge, have a single-line script inserted into the HTML of the page. Using IP filtering techniques, the JavaScript code functions as a traffic distribution system (TDS), directing users to phony CAPTCHA verification pages that employ ClickFix...
TAG-140 Deploys DRAT V2 RAT, Targeting Indian Government, Defense, and Rail Sectors
News

TAG-140 Deploys DRAT V2 RAT, Targeting Indian Government, Defense, and Rail Sectors

A hacker collective with contacts outside of Pakistan has been discovered using a modified version of the remote access trojan (RAT) known as DRAT to target government agencies in India. Recorded Future’s Insikt Group has attributed the activity to a threat actor identified as TAG-140, which it claims overlaps with SideCopy, an adversarial collective evaluated as an operational sub-cluster within Transparent Tribe (also known as APT-C-56, APT36, Datebug, Earth Karkaddan, Mythic Leopard, Operation C-Major, and ProjectM). In an analysis released this month, the Mastercard-owned company claimed that TAG-140 has continuously shown iterative development and variety in its malware arsenal and delivery methods. This most recent attack, which used a fake news release portal to impersonat...