Skip to main content
← All Articles

Tag

#RAT

8 articles

Advertisement

EtherRAT Exploits GitHub Facades to Target High-Privilege Accounts
HIGH
Threat Intel

EtherRAT Exploits GitHub Facades to Target High-Privilege Accounts

A sophisticated campaign uses GitHub Facades and SEO poisoning to distribute EtherRAT by spoofing administrative utilities and DevOps tools.

Runtime Rebel Intel
3 min read·Apr 30, 2026
DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories
CRITICAL
Threat Intel

DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories

DPRK threat actors are employing a 'contagious interview' scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply

Runtime Rebel Intel
5 min read·Apr 22, 2026
REF1695 Operation: ISO Lures Deploy RATs and Crypto Miners
HIGH
Threat Intel

REF1695 Operation: ISO Lures Deploy RATs and Crypto Miners

Financially motivated REF1695 operation uses fake ISO installers to distribute RATs and crypto miners, monetizing infections via cryptojacking and CPA fraud since

Runtime Rebel Intel
4 min read·Apr 2, 2026
MA
HIGH
Malware

CrystalRAT Malware: A New MaaS Threat with RAT, Stealer, and Prankware

CrystalRAT is a new malware-as-a-service (MaaS) promoted on Telegram, offering remote access, data theft, keylogging, and system disruption features, posing a

Runtime Rebel Intel
5 min read·Apr 2, 2026
GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery
HIGH
Malware

GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery

GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.

Runtime Rebel Intel
3 min read·Mar 25, 2026
MA
HIGH
Malware

SmartApeSG Leverages ClickFix Pages to Deploy Remcos RAT

Analysis of the SmartApeSG campaign, detailing its use of deceptive 'ClickFix' pages to distribute Remcos RAT. Learn about RAT capabilities and general mitigation

Runtime Rebel Intel
4 min read·Mar 14, 2026
npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert
HIGH
Supply Chain

npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert

Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.

Runtime Rebel Intel
4 min read·Mar 9, 2026
Malicious Laravel Packagist Packages Deploy Cross-Platform RAT
HIGH
Supply Chain

Malicious Laravel Packagist Packages Deploy Cross-Platform RAT

Security researchers discover malicious Laravel packages on Packagist delivering cross-platform RATs to Windows, macOS, and Linux systems. Audit your PHP dependencies.

Runtime Rebel Intel
3 min read·Mar 4, 2026