Tag

#remote access trojan

12 stories taggedremote access trojan.

Illustration for the story: SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control
Threat Intelligence

SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control

Fortinet's incident responders found a powerful remote-access trojan tucked inside a tampered copy of a real audio program. The malware can grab browser passwords, watch your screen, and hand full control of a Windows PC to criminals.

4 min read
A freelance work platform office with network security analysts reviewing fake account profiles and malicious Excel attachment samples, malware analysis tools r
Threat Intelligence

Russian man charged with infecting 80,000 freelancers through fake Excel attachments

Searzhudin Aktulaev allegedly used 255 fake accounts on a freelance work platform to spread TVRAT and DarkVNC remote-control malware between 2016 and 2017.

4 min read
A computer screen displaying official-looking Cambodian government and health department documents mixed with property listings, all containing malicious file a
Threat Intelligence

Spark RAT campaign hits Cambodia, using fake government and health notices as bait

Attackers are dropping Spark RAT on Cambodian targets through documents dressed as official government notices, health bulletins and property listings, while using a legitimate security driver to blind the victim's defences.

3 min read
A network diagram visualization showing interconnected nodes representing government infrastructure across a map of Central Asia, with several nodes highlighted
Threat Intelligence

SilkParasite: New Espionage Group Hits Central Asian Governments With Five Unseen Hacking Tools

Researchers have named a fresh spying operation running seven remote-access tools against government offices across the region, five of them never seen before.

3 min read
A corporate employee desktop with ScreenConnect remote-access tool running in the background while antivirus software shows a clean status, attacker command pro
Threat Intelligence

Hackers Are Using a Legitimate Remote-Access Tool to Spy on Companies, and Your Antivirus Won't Notice

The Smoke#Screen campaign tricks employees into installing ScreenConnect, a genuine remote-support program, which then hands criminals full control of the victim's computer while looking completely normal to security software.

4 min read
Dark web marketplace forum interface displayed on screens showing Android spyware tool listings and reseller advertisements, multiple vendor profiles and pricin
Threat Intelligence

BTMOB Android spyware splinters into a messy resale market

What started as a single Android remote-access tool for hire has fractured into resellers, source-code buyers and impersonators trading under the same name.

4 min read
An inbox overflowing with official-looking income tax notification emails, with a malware payload invisibly embedded in one highlighted message
Threat Intelligence

Cruciferra: The Malware-Hiding Service Fuelling Attacks on Indian Taxpayers

A China-linked group is paying for a tool called Cruciferra to smuggle remote-access malware onto Windows machines, with fake income tax emails as the entry point.

3 min read
Illustration: a modern Windows laptop on a dark desk
Threat Intelligence

LabubaRAT: New Rust Malware Poses as NVIDIA Software to Sneak Onto Windows PCs

Researchers at Blackpoint Cyber say the newly named tool gives attackers a quiet, reusable way back into infected machines.

3 min read
Illustration: a laptop screen glowing in a dim room showing a formal government tax portal interface with official-looking
Threat Intelligence

Fake Tax Emails Are Planting Two Separate Spying Tools on Indian Taxpayers' Computers

A campaign timed to India's tax filing season tricks people into downloading what looks like an official government utility, and inside are two hidden programs that give criminals full remote control of the victim's machine.

3 min read
Illustration: a modern open-plan office desk at dusk
Threat Intelligence

Fake IT Helpdesk Calls on Microsoft Teams Are Planting EtherRAT on Company PCs

Attackers pose as internal support staff over Teams voice calls, then walk employees through installing remote-access tools that drop a Node.js trojan.

4 min read
Illustration: three different laptops arranged side by side on a dark desk, one Windows machine
Threat Intelligence

QuimaRAT: A New Rent-a-Malware Kit That Hits Windows, Mac and Linux

Researchers at LevelBlue say the Java-based remote access tool is being sold as a subscription, starting at $150 a month, and works across all three major desktop systems.

3 min read
Illustration: a busy international airport terminal, shot from above at dusk
Threat Intelligence

TA558 Is Back, Targeting Hotels and Airlines With Fake Booking Emails

A criminal group that has quietly stolen travel-industry data since 2018 has dramatically ramped up its fake-reservation campaigns, now using compressed file tricks to sneak spying software onto victims' computers.

3 min read
© 2026 Threat Vectr