Tag: remote access trojans (RATs)

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners
News

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners

Since November 2023, a financially driven operation known as REF1695 has been seen using phony installers to distribute bitcoin miners and remote access trojans (RATs). According to an analysis released this week by Elastic Security Labs researchers Jia Yu Chan, Cyril François, and Remco Sprooten, the threat actor monetizes infections through CPA (Cost Per Action) fraud, leading victims to content locker pages under the pretense of software registration. A previously undocumented.NET implant known as CNB Bot has also been discovered to be delivered by recent rounds of the campaign. These assaults employ an ISO file as the infection vector to send the user a text file with clear instructions on how to get around Microsoft Defender SmartScreen's defenses against running unidentified a...
CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users
News

CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users

On Monday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a warning about malicious actors that are actively using remote access trojans (RATs) and commercial spyware to target users of mobile messaging apps. According to the agency, these cyber actors deliver spyware and obtain unauthorized access to a victim's messaging app through sophisticated targeting and social engineering tactics. This enables the deployment of other malicious payloads that may further infect the victim's mobile device. Several campaigns that have surfaced since the beginning of the year were listed by CISA as examples. Among them are the following: Several threat actors with ties to Russia have targeted the Signal communications software, using its "linked devices" functionali...
TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks
News

TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks

The threat actor identified as TA558 has been implicated in a new round of assaults that target hotels in Spanish-speaking markets and Brazil by distributing several remote access trojans (RATs), such as Venom RAT. The behavior, which was noticed in the summer of 2025, is being linked by Russian cybersecurity outfit Kaspersky to a cluster it calls RevengeHotels. Venom RAT implants are still being distributed by the threat actors using JavaScript loaders and PowerShell downloaders through phishing emails with invoice themes, the organization stated. This campaign appears to use large language model (LLM) agents to produce a huge amount of the initial infector and downloader code. The results show a new tendency among cybercriminal organizations to use artificial intelligence (AI) ...
Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
News

Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra

Between May 2024 and July 2025, cybersecurity experts identified five different activity clusters associated with the persistent threat actor Blind Eagle. The Recorded Future Insikt Group saw these attacks, which mostly targeted local, municipal, and federal government officials in Colombia. The activity is being monitored by the threat intelligence company under the TAG-144 label. According to the Mastercard-owned company, the clusters differ greatly in infrastructure, malware deployment, and other operational methods, even though they use similar tactics, techniques, and procedures (TTPs), such as using legitimate internet services (LIS), dynamic domain providers, and open-source and cracked remote access trojans (RATs) for staging. Since at least 2018, Blind Eagle has targeted...
Blind Eagle Uses Proton66 Hosting for Phishing, RAT Deployment on Colombian Banks
News

Blind Eagle Uses Proton66 Hosting for Phishing, RAT Deployment on Colombian Banks

The use of the Russian bulletproof hosting service Proton66 has been strongly linked to the threat actor known as Blind Eagle. In a report released last week, Trustwave SpiderLabs claimed that by diverging from digital assets associated with Proton66, it was able to establish this connection and uncover an active threat cluster that uses Visual Basic Script (VBS) files as its initial attack vector and installs commercially available remote access trojans (RATS). A lot of threat actors use bulletpro.Even though Visual Basic Script (VBS) may seem antiquated, hosting companies like Proton66 continue to use it because they willfully disregard abuse reports and requests for legal takedowns. This facilitates the uninterrupted operation of malware delivery systems, command-and-control serv...
Hackers Exploit Severe PHP Flaw to Deploy Quasar RAT and XMRig Miners
News

Hackers Exploit Severe PHP Flaw to Deploy Quasar RAT and XMRig Miners

Threat actors are delivering remote access trojans (RATs) like Quasar RAT and bitcoin miners by taking advantage of a serious security hole in PHP. The PHP argument injection vulnerability, which has been given the CVE identifier CVE-2024-4577, affects Windows-based systems operating in CGI mode and may enable remote attackers to execute arbitrary code. According to cybersecurity firm Bitdefender, since late last year, there has been a notable increase in exploitation attempts against CVE-2024-4577, with Taiwan accounting for 54.65% of these, Hong Kong for 27.06%, Brazil for 16.39%, Japan for 1.57 percent, and India for 0.33 percent. Approximately 15% of the exploitation attempts that were found were simple vulnerability testing read more about Hackers Exploit Severe PHP Flaw to ...