E4del and PINHOLE RATs Hide Commands in FTP Banners
E4del and PINHOLE use FTP server banners to deliver Windows malware. Check…
Sable Squirrel Uses Expired Domains for Streaming and Malware
Infoblox says Sable Squirrel bought more than 10,000 expired domains for illegal…
How Malware Abused Paste.tc: XWorm, LimeRAT, and AsyncRAT Cases
A cross-case investigation of how AsyncRAT, LimeRAT, and XWorm used Paste.tc raw…
Golden Gh0st RAT: Loader, Risks, and Recovery
Golden Gh0st uses a separate loader to launch a modular remote-access Trojan.…
Heisenberg RAT: Claims, Hidden Desktop Risk, and Removal
See what is verified about Heisenberg RAT, how hidden desktops can expose…
Joyfill npm Packages Compromised: Six Malicious Versions
Six prerelease versions of @joyfill/components and @joyfill/layouts carried an import-time RAT and…
Night Dragon RAT Android Removal: Flying Eagle Cleanup
Remove Night Dragon or Flying Eagle RAT from Android, revoke risky permissions,…
TONResolver RAT Removal: Fake Booking.com Photo Trap
Learn how TONResolver reaches hotel PCs through fake guest-complaint photos, how to…
Operation BlueDash Uses Fake Teams Updates for Remote Access
Operation BlueDash turns a secure-document email into a fake Teams update that…
MedusaHVNC Hijacks Browser Sessions on a Hidden Desktop
BlackFog analyzed MedusaHVNC, a Windows RAT that opens a browser on an…
MarkiRAT Malware Removal: Fake VPNs and svehost.exe
MarkiRAT hides in fake VPN and media-player installers. Check svehost.exe, BITS jobs,…
msaRAT Hides C2 Traffic Inside Chrome and Edge
Cisco Talos found a Rust backdoor that starts a hidden Chrome or…
