Skip to main content
← All Articles

Tag

#RAT

19 articles

Advertisement

MEDIUM
Malware

FTP Banners Abused to Deliver E4del and PINHOLE RATs

Threat actors are using FTP server banners to hide commands, delivering new Windows remote access trojans E4del and PINHOLE via LNK-based infection chains.

Runtime Rebel Intel
4 min read · Aug 24, 2026
SilkParasite Espionage Campaign Targets Central Asian Governments
MEDIUM
Threat Intel

SilkParasite Espionage Campaign Targets Central Asian Governments

SilkParasite espionage campaign targets Central Asian governments with seven remote access tools, including five newly documented RAT families.

Runtime Rebel Intel
3 min read · Aug 19, 2026
msaRAT: Chaos Ransomware's Covert Browser-Based C2
HIGH
Malware

msaRAT: Chaos Ransomware's Covert Browser-Based C2

Cisco Talos uncovers msaRAT, a new Rust-based RAT used by Chaos ransomware for covert C2 via Chrome DevTools Protocol, evading detection.

Runtime Rebel Intel
4 min read · Aug 8, 2026
Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer
HIGH
Supply Chain

Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer

Critical npm supply chain attack involving nearly 800 malicious packages delivers WEL1DROPPER RAT and infostealer to Windows, macOS, and Linux users.

Runtime Rebel Intel
5 min read · Aug 8, 2026
Compromised Joyfill npm Packages Deliver DEV#POPPER RAT
HIGH
Supply Chain

Compromised Joyfill npm Packages Deliver DEV#POPPER RAT

Beta versions of @joyfill/layouts and @joyfill/components npm packages compromised to deliver a DEV#POPPER RAT upon import. Node.js users at risk.

Runtime Rebel Intel
5 min read · Jul 29, 2026
HIGH
Malware

Dolphin X Malware: AI-Driven Target Prioritization & Defense

Analysis of Dolphin X, a new RAT utilizing AI to profile and rank victims, enabling threat actors to prioritize high-value targets for data exfiltration and further…

Runtime Rebel Intel
5 min read · Jul 24, 2026

Advertisement

Malicious Vite npm Packages Deliver RAT via Blockchain C2
HIGH
Supply Chain

Malicious Vite npm Packages Deliver RAT via Blockchain C2

Seven malicious npm packages target Vite frontend projects. Dubbed ViteVenom, this software supply chain attack uses a four-tier blockchain C2 to deploy a RAT.

Runtime Rebel Intel
4 min read · Jul 17, 2026
LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows
HIGH
Malware

LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows

Blackpoint Cyber researchers warn of LabubaRAT, a new Rust-based remote access trojan disguised as NVIDIA software, granting full control over Windows hosts.

Runtime Rebel Intel
4 min read · Jul 14, 2026
MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2
HIGH
Malware

MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2

A new Rust-based MODBEACON RAT, linked to the Silver Fox cybercrime group, employs gRPC streaming for encrypted C2, propagated via SEO poisoning.

Runtime Rebel Intel
5 min read · Jul 10, 2026
Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT
HIGH
Supply Chain

Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT

Security researchers uncover malicious npm packages such as postcss-minify-selector-parser delivering Windows RATs via supply chain attacks. Audit your builds.

Runtime Rebel Intel
3 min read · Jun 23, 2026
EtherRAT Exploits GitHub Facades to Target High-Privilege Accounts
HIGH
Threat Intel

EtherRAT Exploits GitHub Facades to Target High-Privilege Accounts

A sophisticated campaign uses GitHub Facades and SEO poisoning to distribute EtherRAT by spoofing administrative utilities and DevOps tools.

Runtime Rebel Intel
3 min read · Apr 30, 2026
DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories
HIGH
Threat Intel

DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories

DPRK threat actors are employing a 'contagious interview' scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply…

Runtime Rebel Intel
5 min read · Apr 22, 2026
REF1695 Operation: ISO Lures Deploy RATs and Crypto Miners
HIGH
Threat Intel

REF1695 Operation: ISO Lures Deploy RATs and Crypto Miners

Financially motivated REF1695 operation uses fake ISO installers to distribute RATs and crypto miners, monetizing infections via cryptojacking and CPA fraud since…

Runtime Rebel Intel
4 min read · Apr 2, 2026
HIGH
Malware

CrystalRAT Malware: A New MaaS Threat with RAT, Stealer, and Prankware

CrystalRAT is a new malware-as-a-service (MaaS) promoted on Telegram, offering remote access, data theft, keylogging, and system disruption features, posing a…

Runtime Rebel Intel
5 min read · Apr 2, 2026
Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4
HIGH
Supply Chain

Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4

Malicious Axios versions 1.14.1 and 0.30.4 inject a cross-platform RAT via a fake dependency. Identify and remediate this npm supply chain threat now.

Runtime Rebel Intel
4 min read · Mar 31, 2026
GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery
HIGH
Malware

GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery

GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.

Runtime Rebel Intel
3 min read · Mar 25, 2026
HIGH
Malware

SmartApeSG Leverages ClickFix Pages to Deploy Remcos RAT

Analysis of the SmartApeSG campaign, detailing its use of deceptive 'ClickFix' pages to distribute Remcos RAT.

Runtime Rebel Intel
4 min read · Mar 14, 2026
npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert
HIGH
Supply Chain

npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert

Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.

Runtime Rebel Intel
4 min read · Mar 9, 2026
Malicious Laravel Packagist Packages Deploy Cross-Platform RAT
HIGH
Supply Chain

Malicious Laravel Packagist Packages Deploy Cross-Platform RAT

Security researchers discover malicious Laravel packages on Packagist delivering cross-platform RATs to Windows, macOS, and Linux systems. Audit your PHP dependencies.

Runtime Rebel Intel
3 min read · Mar 4, 2026