Skip to content

Topic

Remote Access Trojans

Malware that gives attackers interactive remote control over a compromised device, often used for spying, data theft, or further compromise.

Current stories

security4 publishersConfirmed

Silver Fox delivered ValleyRAT through signed adware that users whitelist themselves

Kaspersky traced one submitted installer to a modified Chinese wallpaper tool whose signed executable sideloads a malicious libcef.dll, and the same installer switches Windows Defender off before it ever runs.

Perspective Coverage

4 publishers
Builder
Builder 24%
Operator
Operator 67%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+15
Incentives30
Confidence66
security4 publishersConfirmed

Mirage Kitten ships Node.js RATs through fake LinkedIn coding challenges

Kaspersky found two cross-platform JavaScript RATs, NodeRabbit and PollCat, reaching engineers in aviation and fintech through fake recruiters, from a group that until now shipped native C, C++ and Go.

Perspective Coverage

4 publishers
Builder
Builder 45%
Operator
Operator 49%
Investor
Investor 6%

Reality

Evidence70
Adoption
Insufficient
Hype gap+15
Incentives35
Confidence65
security6 publishersConfirmed

DOJ extradites a Russian accused of pushing macro malware through 255 fake marketplace accounts

A Northern California freelance marketplace's own messaging system carried Excel macro lures to 80,000 of its users across 18 months. Microsoft closed that delivery step in 2022. The same platform lure now shows up in North Korean operations.

Perspective Coverage

6 publishers
Builder
Builder 17%
Operator
Operator 78%
Investor
Investor 5%

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence68
security1 publisherOne report

Kothamine RAT tunnels its commands through Tailscale's tailcat

Malwarebytes found Kothamine, an undocumented Windows RAT hidden in malicious npm packages, that takes its 30-plus commands over Tailscale's tailcat. The encrypted channel leaves no command-and-control domain to block, pushing detection onto the endpoint.

Publishers:malwarebytes.com

Reality

Evidence60
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence58