Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Neptune RAT

110
Global rank
70 infographic chevron month
Month rank
61 infographic chevron week
Week rank
0
IOCs

Neptune RAT is a Visual Basic .NET remote access trojan that gives attackers full control over infected Windows machines while stealing credentials from 270+ applications, hijacking cryptocurrency transactions, spying on victims in real time, and, in its most destructive mode, wiping the operating system entirely. Marketed openly on GitHub, Telegram, and YouTube as the "Most Advanced RAT," it is distributed under a malware-as-a-service model.

RAT
Type
Unknown
Origin
1 February, 2025
First seen
24 August, 2026
Last seen

How to analyze Neptune RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 February, 2025
First seen
24 August, 2026
Last seen

IOCs

IP addresses
2.18.69.150
150.171.28.11
48.209.138.189
2.18.69.180
150.171.109.194
212.227.108.127
2.16.16.157
40.126.31.67
82.165.179.248
74.178.76.128
150.171.22.17
150.171.109.193
104.18.21.213
104.16.185.241
95.100.102.101
34.237.241.83
208.95.112.1
23.11.40.157
142.251.110.100
54.37.197.40
Hashes
e5ccde87120bb7c5bf898d1b7a7bf45805af8aca9d4e17fe465e8d4a53a72ff0
884b04032e2e70a002956218e8ec3491f2b753c4596cee6e4894dc49afa0a681
63ed103f5076c20b34f36efa685154aaeda7b66c206fa2f2588994fd9c60de7f
251289ce147173263c5fb4529dd91ac4d78139046493f825b11cb02cc6ccc94a
6c433d7e4c8fd4244a6de34c47e029d4a1f9adf3a6bcba5a46a31d22209dce90
0de743cdc71fb1f0f3cfd818950d283f3fd35ab589cb35270d60be4dc4632176
39475df4f91c557ed7e3da8efebcb470a9026b4dd689ddaaf3435392057ea08c
8232c450f967d7f2f22c54582f0667f4c033ae62e6d450ff8a35c47486249443
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
cbc8b288dbd2c72432081cf33cef431572a94c7fb89dbcd59973b99e3871814e
590dfe02709f48f0ba266cf006f527cec4de8b5d0b8baa23e9a0a672b4936fd1
f51a7acfffec56d6751561966d947d3fd199b74528c07dabdcf5fcb33d5b2e85
cd0dd26304b88c20801fe80b33c49c009e2e5d4411b5d7f83252e1d90cd461c6
0fabe1548eba982f5518462f66a451b5c5b45220ac6d84bf029121c02aa258a3
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
7852fce59c67ddf1d6b8b997eaa1adfac004a9f3a91c37295de9223674011fba
81ff65efc4487853bdb4625559e69ab44f19e0f5efbd6d5b2af5e3ab267c8e06
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
Domains
armmf.adobe.com
clients2.googleusercontent.com
api.mylnikov.org
icanhazip.com
ocsp.digicert.com
edge-cloud-resource-static.azureedge.net
copilot.microsoft.com
self.events.data.microsoft.com
activation-v2.sls.microsoft.com
www.bing.com
geo2.adobe.com
settings-win.data.microsoft.com
edge.microsoft.com
fe3cr.delivery.mp.microsoft.com
edge-mobile-static.azureedge.net
update.googleapis.com
slscr.update.microsoft.com
go.microsoft.com
config.edge.skype.com
p13n.adobe.io
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:5rwr_xbxlypjdpcrmmpvaiqwsiftullup52vdv04tk4&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://mc.arbeitsprofi.de/links/eabvamujcddnbgagdjwmceviavddfzmbgagdzgpyauvmfkkidmuxbujnkmsexfmkwaguzwmuxjyvmd/3995744
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://xw.przyjg.net/d.php?s=lexware&h=zwswf4s3&ok=1
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d248%2526e%253d1
https://update.googleapis.com/service/update2/json?cup2key=14:yegcfs25z9ytztbjg8evwq8jljvd7u5blnpqpvja07e&cup2hreq=acdee2b676f6e3300e63bca6192cefd554a2607837e6fdc5c58f161ee4ee4fb3
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://clients2.googleusercontent.com/crx/blobs/abe5cl6a_jaanxapcjclooga79zaaqm3tadaaxpzgbj_5tef2gcwgawlwvojctwjy-62xnz5nkplhywefhkfca7ve1mtom8zrfv598knndu2neqdltxpxs0ljjjkmozedq0axlka5z-i_mcpvgwijs_fx-_dkkqdwg3y/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_109_1_0.crx
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://login.live.com/ppsecure/deviceaddcredential.srf
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
Last Seen at

Recent blog posts

post image
North Korean IT Workers Scheme: Detection IOC...
watchers 6461
comments 0
post image
Hunt Malware & Phishing Threats with ANY....
watchers 6274
comments 0
post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 19615
comments 0

Inside Neptune RAT: How This Multi-Function Malware Steals Credentials, Evades Detection, and Enables Enterprise Attacks

Key Takeaways

  • Neptune RAT combines remote access, credential theft, a cryptocurrency clipper, live surveillance, and destructive capability in a single, actively developed malware-as-a-service package.
  • It is openly distributed through mainstream platforms — GitHub, Telegram, and YouTube — making it accessible to a broad and unpredictable population of attackers.
  • Infection relies on social engineering and PowerShell-based delivery (irm | iex) rather than software exploits, making user awareness and script controls essential defenses.
  • Neptune persists through Registry Run keys and Scheduled Tasks and disables installed antivirus software to extend its presence undetected.
  • Its credential-theft module targets 270+ applications, including Chromium-based browsers, giving attackers a direct path to VPNs, email, and SaaS platforms.
  • SMBs, financial and crypto-related organizations, and businesses with weak PowerShell governance face the highest relative exposure to Neptune's opportunistic distribution model.
  • Security teams can use ANY.RUN's Threat Intelligence Lookup to instantly pivot from a single Neptune indicator to full behavioral context, and ANY.RUN's Threat Intelligence Feeds to block known Neptune infrastructure at the perimeter before the malware can call home.

threatName:"neptune"

Neptune sample analyses in ANY.RUN Sandbox Neptune sample analyses in ANY.RUN Sandbox found via TI Lookup_

What is Neptune RAT Malware?

Neptune RAT first surfaced in early 2025 and quickly drew attention from threat intelligence teams for combining, in a single package, capabilities that are usually spread across several specialized malware families. Written in obfuscated VB.NET, it functions simultaneously as a remote access trojan, an information stealer, a cryptocurrency clipper, a surveillance tool, and — in some builds — a data-destruction utility with ransomware-like behavior.

What sets Neptune apart from the long list of commodity RATs is not any single feature but its packaging and distribution model. Its developers, operating under the "FreeMasonry" banner, promote it publicly as a red-teaming and "educational" tool while simultaneously selling access on Telegram and hinting at a more powerful, paywalled version. Researchers at CYFIRMA and other firms have rejected that framing, pointing to Neptune's anti-analysis techniques, Arabic-character string obfuscation, virtual machine detection, antivirus-disabling routines, and destructive payloads as clear evidence of malicious intent regardless of the stated purpose.

Neptune is delivered through PowerShell one-liners (irm | iex) that fetch and execute a Base64-encoded batch script and payload, frequently hosted on file-sharing services like catbox.moe. Once running, it establishes persistence through Registry Run keys and Scheduled Tasks, disables installed antivirus products, and opens a channel back to the attacker for live desktop monitoring, file exfiltration, credential theft, and remote command execution. The combination of low barrier to entry, broad distribution across mainstream platforms, and a wide feature set has made it a threat that security teams cannot dismiss as "just another RAT."

Because Neptune functions as a multi-purpose attack platform rather than a single-purpose malware family, it can support every stage of an intrusion, from initial compromise and credential theft to lateral movement, data exfiltration, ransomware deployment, and system sabotage.

View Neptune RAT sample analysis in ANY.RUN Sandbox

Neptune RAT attack exposed in Interactive Sandbox NeptuneRAT attack exposed in Interactive Sandbox

How Neptune RAT Threatens Businesses and Organizations

For organizations, Neptune RAT is not a nuisance-grade infostealer — it is a multi-stage business risk generator:

  • Full remote control of endpoints. Once installed, attackers can operate the compromised machine as if sitting in front of it, enabling lateral movement, internal reconnaissance, and staging for follow-on attacks.
  • Mass credential exfiltration. With the ability to pull stored credentials from 270+ applications, including Chromium-based browsers, Neptune can hand attackers a direct path into VPNs, email, SaaS platforms, and internal admin panels — turning one infected laptop into a foothold across the wider corporate environment.
  • Financial fraud via crypto clippers. Any cryptocurrency payment initiated from an infected machine risks being silently redirected to an attacker-controlled wallet, a direct and often irreversible financial loss.
  • Data destruction and business disruption. Neptune's system-destruction capability can render endpoints or servers unusable, creating outages that mirror the operational impact of a ransomware attack — without necessarily involving a ransom negotiation at all.
  • Covert surveillance. Live desktop monitoring lets attackers observe sensitive workflows, internal communications, and confidential business data in real time, ahead of a larger extortion or data-theft campaign.
  • Low cost of entry for attackers. Because Neptune is offered as malware-as-a-service to a broad pool of less-skilled operators, organizations face a wider and less predictable base of potential attackers than they would with a single closed threat actor group.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most at Risk?

Neptune RAT does not appear to target a specific vertical the way some espionage-driven malware does; its MaaS distribution model makes it opportunistic by design. That said, several sectors and organizational profiles carry elevated exposure:

  • Small and mid-sized businesses (SMBs). Limited security tooling, smaller SOC teams, and less mature endpoint monitoring make SMBs more likely to miss the PowerShell-based delivery chain and less likely to catch persistence mechanisms early.
  • Financial services and fintech. The built-in crypto clipper and broad credential-harvesting capability make organizations that handle cryptocurrency transactions or financial credentials a natural high-value target.
  • Individual crypto holders and crypto-adjacent businesses. Given Neptune's clipper functionality is purpose-built around wallet address substitution, exchanges, trading desks, and crypto-native companies face direct financial exposure.
  • Content creators, gamers, and tech-adjacent communities. Because Neptune spreads via YouTube tutorials, "free tool" GitHub repositories, and Telegram channels, users and businesses whose staff frequent these platforms for research or content are at elevated risk of drive-by installation through social engineering.
  • Organizations with weak PowerShell governance. Since delivery hinges on unrestricted execution of irm | iex commands, any environment without PowerShell execution policy controls, script block logging, or endpoint detection tuned to this pattern is more exposed.
  • Managed service providers (MSPs) and IT resellers. A single infected technician machine with broad client access can turn Neptune into a supply-chain-style incident affecting multiple downstream customers.

The Evolution of Neptune RAT and Notable Activity

Neptune RAT's public timeline reflects a rapid, iterative development cycle typical of actively maintained MaaS tooling:

  • Early 2025 — Initial discovery. Neptune RAT is identified in the wild, distributed as a heavily obfuscated VB.NET executable and promoted on GitHub, Telegram, and YouTube under the "Most Advanced RAT" tagline.
  • Version with direct PowerShell builder integration. A subsequent version adds the ability to generate ready-to-use irm | iex PowerShell one-liners directly from the malware's builder interface, lowering the technical bar for operators to weaponize and deploy it.
  • Expanded credential-theft scope. Later builds extend password-stealing coverage to 270+ applications and introduce a dedicated Chromium-targeting stealer component (internally referenced as "Chromium.dll" in analyzed samples) capable of decrypting stored browser credentials across Chrome, Brave, Opera, and other Chromium-based browsers.
  • Destructive capability added. A version emerges with the ability to corrupt or destroy the Windows operating system on the victim machine, moving Neptune from "espionage/theft tool" into territory that overlaps with wiper and ransomware-class malware.
  • Source-unavailable release. In a departure from earlier open distribution, the developer releases a version without accompanying source code, deliberately increasing obfuscation to complicate researcher analysis while continuing sales through the same channels.
  • Ongoing "paywalled" tier. Public statements from the malware's developers reference a more advanced, non-public version available for a fee, suggesting Neptune continues to be actively developed and monetized as a tiered commercial product rather than a one-off release.

Because Neptune is distributed through open platforms rather than a single closed criminal infrastructure, individual "notable attacks" are harder to attribute to named victims than with a targeted APT campaign — the more accurate picture is one of continuous, broad-based opportunistic infection driven by its accessibility to a large population of less-sophisticated operators.

How Neptune RAT Gets Into Systems and Spreads

Neptune's infection chain relies on social engineering and trusted-platform abuse rather than exploiting software vulnerabilities:

  • 1. Lure and distribution. Neptune is promoted through YouTube videos (often disguised as "free tool," "game cheat," or "crack" tutorials), GitHub repositories, and Telegram channels, all platforms that carry inherent user trust.
  • 2. Delivery mechanism. Victims are guided to run a PowerShell command using irm (Invoke-RestMethod) to download a script and iex (Invoke-Expression) to execute it directly in memory — a technique that avoids writing an obvious executable to disk before execution begins.
  • 3. Payload staging. The PowerShell command retrieves a Base64-encoded batch script and the Neptune payload, frequently hosted on file-sharing services such as catbox.moe, and drops the decoded components into the AppData folder.
  • 4. Execution and callback. Once executed, the payload establishes a connection back to the attacker's command-and-control infrastructure, completing the initial compromise. Persistence. Neptune secures long-term presence by writing Registry Run key entries and creating Scheduled Tasks, ensuring it survives reboots without requiring repeated user interaction.
  • 5. Defense evasion. The malware disables installed antivirus software and, in some variants, deletes artifacts of its own activity to hinder incident response and forensic reconstruction.
  • **6. Lateral risk. While Neptune itself is primarily an endpoint-level threat, harvested credentials (VPN, email, SaaS, admin panels) can be reused by attackers to pivot further into an organization's network.

How Neptune RAT Malware Functions

Neptune's functionality is best understood as a set of coordinated modules operating under one RAT framework:

  • Obfuscation and anti-analysis. Executables show high entropy in their code sections, use a custom string heap to store sensitive strings and decryption keys, and substitute original strings with Arabic characters, all aimed at frustrating static analysis. Built-in virtual machine detection lets the malware alter or halt its behavior when it suspects it is running inside a sandbox.
  • Persistence layer. Registry modifications and Scheduled Task creation keep Neptune running across reboots without further user action.
  • Credential theft module. A dedicated stealer component targets Chromium-based browsers (Chrome, Brave, Opera, and others), extracting encrypted credential stores from local application data, decrypting them, and exfiltrating the results. Overall password-theft coverage spans 270+ applications.
  • Cryptocurrency clipper. Neptune monitors the system clipboard using regex pattern matching to detect copied cryptocurrency wallet addresses. When a match is found, it silently substitutes the attacker's wallet address of the matching type, redirecting funds at the moment a victim completes a transaction.
  • Live desktop monitoring. Remote surveillance capability allows operators to watch victim activity in real time, extending Neptune's reach well beyond one-time data theft.
  • Antivirus disablement. Built-in routines disable installed security software, reducing the chance that later stages of the attack, or follow-on payloads, are detected and blocked.
  • Destructive/ransomware capability. Certain builds include functionality to corrupt or destroy the Windows operating system, giving Neptune's operators an option to cause outright system failure rather than, or in addition to, quiet data theft.
  • Command-and-control communication. Neptune communicates with attacker infrastructure over standard web protocols, and its PowerShell-based delivery chain (using irm/iex) allows operators to update or redeploy payloads with minimal friction.

View the attack chain in ANY.RUN Interactive Sandbox:

Neptune RAT detonated in Interactive Sandbox Neptune RAT detonated in Interactive Sandbox

The analyzed sample of Neptune RAT, after launching the BAT file, initiates the execution of a PowerShell script. The script runs in hidden mode and bypasses script execution restrictions, which allows the malicious code to execute without noticeable user interaction. This approach is used to mask the initial activity, reduce the likelihood of detection, and prepare for the execution of the next stage of malicious logic.

Neptune initial script Neptune initial script

Additionally, the command is transmitted in encoded form and is only revealed during execution, which complicates static analysis and hides the contents of the subsequent script.

The encoded command The encoded command

Next, the sample creates a BAT file in the user’s Windows autostart directory. This mechanism is used for persistence in the system: the contents of this directory are automatically launched upon the user’s subsequent login. Thus, the malicious program ensures repeated execution after a reboot or re-authentication of the user.

The persistence mechanism The persistence mechanism

Furthermore, in the behavior of the PowerShell script, the use of symmetric AES encryption is observed. The script sets a key and initialization vector, after which it uses them to process embedded data.

AES encryption

AES encryption AES encryption

Additionally, operations with GZIP are observed, indicating another layer of payload packing.

GZIP file operations GZIP file operations

On the network side, the sample uses a TCP connection to the C2 server via the domain: apostlejob3[.]duckdns[.]org:2468.

C2 TCP connection C2 TCP connection

Also, in the analysis, successful extraction of the sample’s configuration can be seen. It specifies the C2 server and additional information about the malware’s contents.

Neptune malware configuration Neptune malware configuration

How Businesses Can Use ANY.RUN’s Threat Intelligence Solutions Against Neptune RAT

Because Neptune relies heavily on a recognizable delivery pattern — public-platform lures, PowerShell one-liners, catbox.moe-style payload hosting, and a consistent persistence and evasion toolkit — organizations have a real opportunity to detect it before impact, provided they have visibility into both the behavioral pattern and the current indicator landscape.

ANY.RUN Threat Intelligence Lookup lets analysts pivot from a single known Neptune indicator — a suspicious hash, a catbox[.]moe URL, a C2 domain, a registry key used for persistence, or a PowerShell command pattern — to the full corresponding sandbox session, instantly surfacing related samples, associated infrastructure, and behavioral context drawn from millions of public analyses. When a SOC analyst spots a PowerShell command using irm | iex in an alert, TI Lookup can confirm within minutes whether it matches known Neptune activity rather than requiring a full manual investigation, cutting triage time significantly and reducing unnecessary escalations from Tier 1 to Tier 2.

ANY.RUN Threat Intelligence Feeds deliver continuously updated streams of malicious IPs, domains, and URLs sourced from real-world sandbox detonations across a global analyst community. Ingested into a SIEM, SOAR, IDS/IPS, or firewall, these feeds allow organizations to block known Neptune C2 infrastructure and payload-hosting domains at the perimeter — stopping the malware before its PowerShell stager can even complete a callback, rather than relying solely on after-the-fact endpoint detection.

Used together, TI Lookup and TI Feeds give security teams both the forward-looking blocking layer (Feeds) and the investigative depth (Lookup) needed to handle a fast-evolving, opportunistically distributed threat like Neptune, where new samples, hashes, and hosting domains appear continuously across GitHub, Telegram, and YouTube.

Beyond threat intelligence, organizations should combine several additional layers of defense:

  • PowerShell hardening. Enforce constrained language mode, enable script block logging, and restrict or monitor Invoke-RestMethod/Invoke-Expression usage across endpoints. Application and script controls. Use application allowlisting to prevent unauthorized executables and scripts from running, particularly from AppData and other user-writable directories.
  • Endpoint detection and response (EDR). Deploy EDR tuned to detect Registry Run key modifications, unusual Scheduled Task creation, and antivirus-tampering behavior.
  • Interactive sandbox analysis. Detonate suspicious downloads and PowerShell payloads in an interactive sandbox such as ANY.RUN's Interactive Sandbox to observe real behavior, including sandbox-evasion attempts, before they reach production systems.
  • Employee awareness training. Educate staff on the risks of running commands or downloading "free tools," cracks, or cheats from YouTube, GitHub, and Telegram sources.
  • Credential hygiene. Enforce multi-factor authentication across VPN, email, and SaaS platforms so that stolen browser credentials alone are insufficient for an attacker to pivot further into the network.
  • Backup and recovery planning. Maintain offline or immutable backups to ensure Neptune's destructive capability cannot translate into permanent data loss.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Neptune RAT illustrates how much damage a single, actively maintained malware-as-a-service package can now cause once it combines remote access, credential theft, financial fraud, surveillance, and destructive capability in one accessible tool. Its reliance on mainstream platforms for distribution and a recognizable PowerShell-based delivery chain means it is neither invisible nor unstoppable — but it does demand that organizations pair strong technical controls with continuously updated, real-world threat intelligence. Treating Neptune as "just another RAT" risks underestimating both its reach and its potential for outright business disruption.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Pay2Key screenshot
Pay2Key is a ransomware strain primarily written in C++ for Windows (with recent Linux variants), attributed to Iranian-linked actors, notably the Fox Kitten APT group (also known as UNC757 or related operations). First observed in late 2020, it employs double-extortion tactics (encrypting files and threatening to leak stolen data) while showing signs of both financial and state-aligned motivations. It has resurfaced in campaigns targeting Western organizations, including rapid encryption attacks on healthcare.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More
DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
Orcus RAT screenshot
Orcus RAT
orcus rat trojan
Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class.
Read More
StrelaStealer screenshot
StrelaStealer
strela
StrelaStealer is a malware that targets email clients to steal login credentials, sending them back to the attacker’s command-and-control server. Since its emergence in 2022, it has been involved in numerous large-scale email campaigns, primarily affecting organizations in the EU and U.S. The malware’s tactics continue to evolve, with attackers frequently changing attachment file formats and updating the DLL payload to evade detection.
Read More
Wshrat screenshot
Wshrat
wshrat rat trojan
WSHRAT is a Remote Access Trojan — a malware that allows the attackers to take over the infected machines. The RAT has been in circulation since 2013 and it is arguably most notable for the numerous versions released into the wild.
Read More