Skip to content
Threat Feed

Tag

Remote-Access-Trojan

7 briefs RSS
high advisory

SectopRAT Variant Distributed via Tampered Software Installers

Threat actors are distributing a variant of SectopRAT by embedding the malware into legitimate software installers, enabling remote control and credential theft upon execution.

remote-access-trojan sectoprat malware windows credential-theft
3t
high advisory

Cross-Platform Malware Campaign via Malicious Google Doc Sidebar

A social engineering campaign delivered via X direct messages leverages a Google Doc sidebar to deliver platform-specific malware, deploying NetSupport Manager on Windows and Atomic macOS Stealer (AMOS) on macOS.

social-engineering malware stealer remote-access-trojan x-social-media
2t
high threat

CL-CRI-1171 Pay-Per-Install Infrastructure and Malware Campaign

The CL-CRI-1171 threat actor operates a large-scale pay-per-install marketplace, leveraging SEO poisoning and YouTube gaming lures to deploy a persistent multi-payload loader used to distribute malware including Insomnia RAT and ARKTunnel.

WinDirStat CL-CRI-1171 ppi malware seo-poisoning loader remote-access-trojan c2
1r 2t 5i
critical advisory

Zbtlink Router Firmware Contains Embedded ENDLESSDOORS Implant

Zbtlink router firmware ships with the ENDLESSDOORS remote-control implant, which runs as root, masquerades as a kernel process, and enables unauthenticated remote command execution.

PoC Router Firmware +20 supply-chain firmware backdoors remote-access-trojan network-security
3t 1c updated
high advisory

CastleLoader Malware Loader and ClearFake Activity in July 2026

Red Canary reports heightened activity of the CastleLoader malware loader, which uses paste-and-run techniques and legitimate tools to deliver infostealers and RATs, alongside continued prevalence of the ClearFake activity cluster in June 2026.

malware loader infostealer remote-access-trojan paste-and-run drive-by download windows
3r 7t 7i
high advisory

Unpacking 'Cruciferra': Analysis of a Sophisticated Crypter Service

Cruciferra is a sophisticated crypter-as-a-service, written in Mono, actively developed and sold to multiple cybercriminal threat actors who use it to deliver a wide range of remote access trojans and infostealers, employing extensive defense evasion techniques like BYOVD-based EDR tampering, Process Ghosting, and unique cryptographic obfuscation via email-based phishing campaigns.

crypter malware-as-a-service defense-evasion remote-access-trojan infostealer windows
1r 10t 11i
critical advisory

Detection of Malicious Remote Access Tools by Antivirus

This brief details a Sigma rule designed to detect Antivirus alerts flagging various malicious Remote Access Tools (RATs) such as AgentTesla, AsyncRAT, and NanoCore, highlighting the critical need for investigation into the initial infection vector even when the AV blocks the threat.

remote-access-trojan rat antivirus detection malware windows
1r 1t