Friday 11 September 2026 12:58:33 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

#remote access trojan


SloppyRAT Adds a Quiet Layer Before Ransomware Strikes

Published: 11 September 2026 10:55Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A newly identified remote access trojan, a multi-stage ClickFix chain, and blockchain-based control suggest a malware path built for persistence and stealth, not just immediate disruption.

Fake Game Builds, Real Damage: How a GTA VI Lure Can Turn Into Malware

Published: 10 September 2026 14:21Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A hype-fueled download bait is being used to push password stealers, RATs, and destructive payloads through convincing fake game files.

The Job Interview Was the Payload: A Developer Lure Now Carries Cross-Platform Malware

Published: 09 September 2026 18:57Category: Cyber Warfare & Nation-State OperationsGeo: Africa / EgyptAuthor: AGONY

Fake recruiter outreach and trojanized coding assessments are turning routine hiring conversations into a delivery path for previously undocumented RATs aimed at developer machines.

Mac Installers Turn Into Delivery Traps in a New OtterCookie Push

Published: 04 September 2026 10:34Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

Trojanized DMG and PKG files are being used to push OtterCookie RAT through a Contagious Interview-linked campaign, turning ordinary software trust into the attack path.

Streaming Lure, Silent Hands: How StreamRAT Turns Android Permissions into Remote Control

Published: 03 September 2026 10:11Category: Malware & BotnetsGeo: Europe / SpainAuthor: IRONQUERY

A streaming-themed Android campaign shows how a single accessibility grant, paired with VNC-style control, can turn a consumer phone into an operator-driven device.

Wallet-Branded Installers Are Becoming Perfect Delivery Vehicles for Browser Theft

Published: 02 September 2026 20:30Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A trojanized Exodus wallet installer is being used to drop a modular RAT that focuses on credentials, cookies, and live operator access rather than a quick hit on crypto balances.

The Job Test That Might Not Be a Test

Published: 01 September 2026 14:09Category: Malware & BotnetsGeo: Middle East / IranAuthor: SIGNALMONK

Fake coding exercises are being used as a malware lure against developers, with researchers attributing the campaign with high confidence to Mirage Kitten.

Tax Lures, Modular Malware, and the Quiet Return of Packaged Access

Published: 29 August 2026 10:05Category: Malware & BotnetsGeo: Asia / ChinaAuthor: SIGNALMONK

A phishing chain tied to the cluster tracked as TA4922 shows how tax-themed email can be turned into a delivery path for a modular RAT, staged loaders, and follow-on access tooling.

Tax Notices, Telegram Sales, and a Modular RAT: The Quiet Machinery Behind a Phishing Run

Published: 29 August 2026 08:04Category: Malware & BotnetsGeo: Asia / ChinaAuthor: SIGNALMONK

A tax-themed lure linked to TA4922 shows how localized phishing and commodity malware can be fused into a repeatable access playbook without proving full compromise.

Spark RAT in Cambodia: When a Familiar Trap Meets a Weakened Defense Layer

Published: 27 August 2026 14:23Category: Malware & BotnetsGeo: Asia / CambodiaAuthor: SIGNALMONK

A malware campaign aimed at Cambodian users and organizations combines social engineering with a vulnerable driver to make endpoint protection harder to trust.

Core Werewolf’s Quiet Upgrade: Why a Custom RAT Matters More Than a New Malware Name

Published: 26 August 2026 08:17Category: Malware & BotnetsGeo: Europe / RussiaAuthor: NEXUSGUARDIAN

A Russia-focused espionage cluster is now being linked to CoreRAT, a homegrown implant that marks a shift away from borrowed remote-control tools and toward tighter operator control.

CoreRAT Turns a Windows Breach Into a Quiet Operator Console

Published: 26 August 2026 08:03Category: Malware & BotnetsGeo: Europe / RussiaAuthor: NEXUSGUARDIAN

A custom remote access trojan linked to Core Werewolf shows how espionage crews can turn infected Windows systems into interactive workspaces for command execution, information gathering, payload downloads, and cleanup.

FTP’s Forgotten Greeting Is Becoming a Malware Blind Spot

Published: 25 August 2026 17:10Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A campaign tied to two newly named RAT families uses FTP banners as dead drop resolvers, showing how a routine protocol greeting can be turned into a covert routing layer.

FTP’s Quietest Message Turned Into a Malware Delivery Trick

Published: 21 August 2026 14:19Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

Security researchers traced a campaign that hides commands in FTP server banners to help deliver two previously undocumented Windows RATs, E4del and PINHOLE.

Seven RAT Families, One Quiet Campaign: What SilkParasite Suggests About Espionage in Central Asia

Published: 21 August 2026 10:30Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

A multi-implant intrusion set aimed at government networks shows how modern espionage can be built for persistence, redundancy, and hard-to-trace access.

SilkParasite and the Quiet Logic of Multi-RAT Espionage

Published: 20 August 2026 12:19Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

A Central Asia-focused intrusion cluster linked to seven RAT families shows why defenders should hunt for behavior, not cling to a single malware name.

When a Search Ad Becomes the Malware Loader

Published: 19 August 2026 10:35Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A lure built around Claude installation help shows how sponsored search, trusted web properties, and macOS prompts can be stacked into one convincing credential-theft chain.

Fake Claude Install Guides Become a Trapdoor for Mac Password Theft

Published: 19 August 2026 10:29Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A convincing software-onboarding lure is being used to push Mac users toward MacSync, turning search trust into a route to credential theft and crypto wallet risk.

The Job Interview Trap That Turned a Signed Installer Into a Security Event

Published: 17 August 2026 08:08Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

A fake recruiting flow, a cloud-doc decoy, and a trusted Windows install path formed a chain that could push a target from conversation to compromise without a classic exploit.

The Hidden Windows Trick Behind a DCRat Phishing Run

Published: 14 August 2026 12:07Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A legal-themed email, an SVG file, and two classic Windows trust-abuse techniques show how commodity malware can disappear into ordinary process activity.