#RAT
9 stories taggedRAT.

Hackers Hide Malware Instructions in FTP Server Greetings
A quiet trick spotted by SOCRadar uses FTP welcome messages to smuggle commands onto Windows machines, dropping two new remote-control tools called E4del and PINHOLE.

Fake Roblox Cheat Tool Hides Password Stealer and Remote Spy Software
Bitdefender says a months-long campaign is pushing booby-trapped copies of the Xeno script runner to Roblox players, planting malware that steals browser logins, drains crypto wallets and hands attackers full control of the PC.

Fake npm Packages Pose as Alibaba Developer Tools, Drop Remote-Control Malware
Researchers found 18 booby-trapped packages on the npm registry aimed at Chinese-speaking developers, using a classic name-squatting trick to smuggle in a cross-platform remote access trojan.

Flying Eagle Android Spyware Kit Leaks Onto Telegram, Traced to 170 Servers
Researchers link the free-to-copy surveillance toolkit to a fake Chinese police services app aimed at Android phone users.

Booby-trapped @joyfill npm packages hide a remote-control trojan
Two beta versions of the popular Joyfill JavaScript packages were tampered with to plant malware that runs the moment a developer imports them.

Dolphin X: The New Malware That Uses AI to Pick Which Victims to Rob First
A remote access trojan sold on a cybercrime forum claims to score infected computers by their value, helping criminals go after the richest targets first.

Silver Fox's New MODBEACON Trojan Hides Inside Fake Software Installers
The China-linked group is using booby-trapped downloads to plant a Rust-built remote-control tool that talks to its handlers over encrypted channels.

ChocoPoC RAT Hides in Fake GitHub Exploits, Targets Security Researchers
A cluster of trojanized proof-of-concept repositories is pushing a Python-based RAT to the very people who go looking for them.

DesckVB RAT Campaign Routes Phishing Lures Through Google's DoubleClick Domain
Attackers are bouncing victims off a Google-owned ad redirect before landing them on attacker infrastructure — a trick that buys cover from filters trained to trust doubleclick.net.