Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Overlord RAT

42
Global rank
33 infographic chevron month
Month rank
20 infographic chevron week
Week rank

Overlord RAT is a cross-platform remote access framework with Go-based agents and a TypeScript/Node/Bun server. It supports encrypted WebSocket C2, remote control, persistence, and multiple operating systems, including Windows, Linux, and macOS.

RAT
Type
Unknown
Origin
1 June, 2026
First seen
2 October, 2026
Last seen

How to analyze Overlord RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 June, 2026
First seen
2 October, 2026
Last seen

IOCs

IP addresses
2.23.246.101
135.233.95.144
2.23.246.9
172.211.123.248
23.11.41.157
20.190.160.67
48.192.1.64
2.16.110.138
172.86.85.146
2.16.110.155
48.209.138.168
23.194.190.156
20.165.94.54
2.21.239.138
23.48.23.35
131.253.33.203
2.16.204.140
74.178.76.128
2.16.204.151
23.52.181.212
Hashes
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
4dbfc417d053ba6867308671f1c61f4dcafc61f058d4044db532da6d3bde3615
25973a78051dcbfe80b2cbf4db85b2dd14a913d294b48b2dfbdf3619fe8c3140
c030e91159dd7ef6a3447f4d24e43dae5f7e8d98ac02ae95e36873e2f6cffe57
37d5c850ae291b7dc43e80005ee80a361701d70044ad1d2e2fe7442313ee63c2
12862f6e181922c4b652768cf8d4128626b83631b1990e9b8df54be2b725bc5d
4cf4ba3c64c5ac896a319bd0ebbf0768be14d42e48fc14702abe23810a359646
725c83a3d30ea5d814723551acada060dce1a8a05865f314916962c80a6af397
ed4177309d04ecda29dbcabd521a31ad2c63982bf9af0d5c9be50105671a70ec
9025617ede362d5c1c6af47f4d0d8c6ede386d0bb20174799090341dce8029b2
b88a1875976e2e0df054ace750af1f1925aa46e7900396de173d67cf70eb2e53
b3d5002ca2a988c0ae2e854eb1c865dd9c57867b56668687e01c16df573ac9f9
329b20f56d6438f20aef784d9bd7b686dd16550dc84967bb5be3dc0a1c29ce18
16ce95d9bc2ba6a7e62fb16f19208ffe3f73f81cf2993f86dc5d6fa88443a43f
6f0f4073a60a2497ef460238a6888a4e4534c59d97f412558e293d1c1ce42a60
498e3205bf85da0a8f8b57e292d4bd12b31d691e04039c04bedcde75d1ea7459
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
3615498fbef408a96bf30e01c318dac2d5451b054998119080e7faac5995f590
Domains
client.wns.windows.com
dns.msftncsi.com
crl.microsoft.com
oneocsp.microsoft.com
www.microsoft.com
ocsp.digicert.com
settings-win.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
www.bing.com
nexusrules.officeapps.live.com
go.microsoft.com
self.events.data.microsoft.com
th.bing.com
ecs.office.com
google.com
login.live.com
activation-v2.sls.microsoft.com
sb-ssl.google.com
safebrowsingohttpgateway.googleapis.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://www.bing.com/dsb/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=us&setlang=en-us&clientdatetime=10%2f2%2f2026%2c%201%3a28%3a00%20pm
https://www.bing.com/dsb/scenario?name=trendingsearchwithcache&cc=us&setlang=en-us
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/th?id=odswg.43f97539-d796-4888-810f-8ca2a5cbb8ab&pid=dsb
https://th.bing.com/th?id=odswg.iotdlocalicon&w=16&h=16&c=1&rs=1&p=0
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=p&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=1&cvid=9f3558f9247046de952429f1922c290c&ig=944d6580bb08464c8551357ac4853c29
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=po&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=2&cvid=9f3558f9247046de952429f1922c290c&ig=1f17c48dc8da47d9989885522de944bd
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=pow&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=3&cvid=9f3558f9247046de952429f1922c290c&ig=8a6093b473a741858d0bc93b47b1b0b6
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=powe&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=4&cvid=9f3558f9247046de952429f1922c290c&ig=eef8dcd2c46046ccb8017fe1588ce03a
Last Seen at

Recent blog posts

post image
Threat Coverage Digest: New Malware Reports a...
watchers 2482
comments 0
post image
Phishing Response Protocol: 3 Essential SOC S...
watchers 4971
comments 0
post image
Major Cyber Attacks in September 2026: US and...
watchers 8357
comments 0

Key Takeaways

  • Cross-Platform RAT: Overlord RAT is a publicly available cross-platform RAT framework with Go-based agents and a server component built with TypeScript and Node/Bun.
  • Remote Access: The framework provides operators with remote access to compromised systems through a centralized C2 infrastructure.
  • Encrypted C2: Overlord RAT supports encrypted WebSocket communication using WSS for communication between agents and the C2 server.
  • Web-Based Control: Operators can manage connected agents through a web-based interface or Electron client.
  • Persistence: Overlord RAT supports mechanisms that can help maintain access to compromised systems beyond the initial execution.
  • Masquerading: The framework can employ techniques such as legitimate-looking filenames or system component names to make malicious activity less conspicuous.
  • C2 Tunneling: Overlord RAT can use tunneling services such as ngrok as part of its C2 infrastructure, potentially obscuring the underlying server.
  • Multi-Platform Support: The framework supports Windows, Linux, and macOS, allowing it to operate across different operating system environments.
  • ANY.RUN’s Interactive Sandbox analysis provides visibility into Overlord RAT’s execution behavior, including host discovery, remote communication, and activity performed after the malware becomes active on the system.

Overlord RAT detonated inside ANY.RUN’s Interactive Sandbox

Overlord RAT detonated inside ANY.RUN’s Interactive Sandbox

What is Overlord RAT?

Overlord RAT is a publicly available cross-platform remote access trojan (RAT) framework designed to provide remote access to compromised systems.

The framework uses Go-based agents, while its server-side components are implemented using TypeScript with Node.js/Bun. Operators can manage connected agents through a web-based interface or an Electron client.

Communication between agents and the C2 server takes place over encrypted WebSocket connections (WSS), providing a channel for exchanging commands and information.

The framework supports Windows, Linux, and macOS, making it applicable across multiple operating system environments. Its continued development also means that capabilities and implementation details may change between versions.

How Overlord RAT Affects Businesses and Organizations

An Overlord RAT infection can create several risks for organizations, including:

  • Unauthorized remote access: The RAT can provide an operator with remote access to a compromised endpoint.
  • Persistence: The Windows sample analyzed in this article uses multiple persistence mechanisms to maintain access after execution.
  • System masquerading: Names associated with legitimate Windows processes and components can make malicious activity less obvious during an initial investigation.
  • C2 exposure: Communication with remote infrastructure provides an external channel through which an operator can control an infected system.
  • Infrastructure concealment: The observed use of an ngrok tunnel can make identifying the attacker's underlying infrastructure more difficult.
  • Cross-platform exposure: Because the framework supports Windows, Linux, and macOS, organizations using different operating systems may need to account for the framework across multiple environments.
  • Follow-on activity: Remote access can provide an operator with an entry point for additional activity on the compromised system.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Potential Targets of Overlord RAT

Overlord RAT supports Windows, Linux, and macOS, potentially exposing organizations that operate mixed-OS environments.

The framework is not described as being restricted to a specific industry or sector. Its general-purpose remote-access capabilities can potentially be applied to a broad range of environments.

The impact of an infection can depend on the privileges available to the compromised agent, the system on which it is running, the configuration of the RAT, and the actions performed by the operator.

How Does Overlord RAT Function?

Observing an Overlord RAT sample inside ANY.RUN’s Interactive Sandbox shows that Overlord RAT uses a client-server architecture in which lightweight agents communicate with a central server operated through a web-based or Electron interface.

The agents are written in Go, while the server component uses TypeScript and Node.js/Bun. Communication between agents and the server takes place over encrypted WebSockets (WSS).

The observed Windows sample additionally uses several techniques intended to maintain access and make the malware appear less suspicious.

The general execution flow can be summarized as:

Agent execution → Persistence → Process masquerading → Encrypted C2 communication → Remote control

Overlord RAT detected in ANY.RUN’s Interactive Sandbox

Overlord RAT detected in ANY.RUN’s Interactive Sandbox

Stage 1: Agent Execution

Overlord RAT operates through an agent deployed to the target system.

The framework supports multiple operating systems, including Windows, Linux, and macOS. The Go-based agent is responsible for establishing communication with the server and carrying out actions received through the C2 channel.

On Windows, the analyzed sample is named: svchost-windows-amd64-a8d100a3.exe

The filename resembles the naming convention used by legitimate Windows system processes, helping the executable blend into the host environment.

Stage 2: Persistence Through Multiple Locations

The analyzed Windows sample establishes persistence using more than one mechanism.

First, the malware copies itself to: AppData\Roaming\Microsoft\DeviceSync\svchost.exe

It also places a copy in the Startup folder, allowing the malicious executable to be launched when the user logs into Windows.

Overlord RAT copies itself as svchost.exe to DeviceSync and Startup folder

Overlord RAT copies itself as svchost.exe to DeviceSync and Startup folder

In addition, the sample modifies a Windows Registry autorun key to establish another startup mechanism.

Registry autorun key modification for persistence

Registry autorun key modification for persistence

This combination provides redundant persistence, meaning that the malware has multiple ways to regain execution if one mechanism is removed.

Stage 3: Mutex Masquerading

The sample creates a mutex using a name associated with a legitimate Windows component: Global\BFE_Notify_Event_{...}

Overlord RAT masquerades as legitimate Windows BFE component mutex

Overlord RAT masquerades as legitimate Windows BFE component mutex

The use of a name associated with the Windows Base Filtering Engine (BFE) can make the mutex appear less suspicious during analysis and may help the malware avoid standing out among legitimate system objects.

A mutex can also help malware coordinate execution and prevent multiple instances of the same component from running simultaneously.

Stage 4: Encrypted C2 Communication

After establishing itself on the system, the agent communicates with the Overlord server using encrypted WebSocket connections (WSS).

This provides a persistent communication channel through which the agent and server can exchange information and commands.

The framework's server component is implemented using TypeScript and Node.js/Bun, while operators can interact with connected agents through a web panel or Electron client.

Stage 5: C2 Through an Ngrok Tunnel

The analyzed sample communicates with its C2 through an ngrok tunnel.

C2 via ngrok tunnel

C2 via ngrok tunnel

Ngrok provides a tunnel between the infected system and the remote service, which can obscure the attacker's underlying infrastructure from the victim's network.

For defenders, this means that the visible destination may belong to the tunneling service rather than directly revealing the infrastructure operated by the attacker.

Stage 6: Remote Control

Once the agent establishes its C2 connection, the framework provides the operator with a mechanism for remotely managing the compromised host.

Commands can be issued through the framework's control interface and transmitted to connected agents through the C2 channel.

This remote-access capability is the central function of Overlord RAT and distinguishes it from malware designed solely for information collection or payload delivery.

Stage 7: Persistence

Unlike Windows-only RATs, Overlord is designed as a cross-platform framework. Its agents support Windows, Linux, and macOS.

This architecture allows the same broader framework to be deployed across different operating system environments, although specific functionality may depend on the agent and platform.

Understanding Overlord RAT Behavior

The analyzed Windows sample demonstrates several notable behaviors:

  • Go-based agent provides the malware's endpoint component.
  • Windows process masquerading uses the filename svchost-windows-amd64-a8d100a3.exe.
  • Multiple persistence mechanisms place copies in the DeviceSync directory and Startup folder while modifying a Registry autorun key.
  • Mutex masquerading uses a name associated with the legitimate Windows BFE component.
  • Encrypted WebSocket communication provides the C2 channel between the agent and server.
  • Ngrok tunneling is used to route C2 traffic and conceal the underlying infrastructure.
  • Web/Electron management provides operators with an interface for controlling connected agents.
  • Cross-platform support extends the framework to Windows, Linux, and macOS.

Together, these capabilities allow Overlord RAT to establish a persistent presence, communicate with remote infrastructure, and provide operators with remote access to compromised systems.

How Threat Intelligence Can Help Investigate Overlord RAT

Because Overlord is a developing RAT/framework, samples may differ in configuration, filenames, infrastructure, and implementation. Defenders should therefore combine static indicators with behavioral and network analysis.

ANY.RUN’s Threat Intelligence can help analysts investigate suspicious Overlord activity by connecting samples with associated infrastructure and observable behaviors.

Threat Intelligence Lookup can be used to pivot from a suspicious sample or indicator toward:

  • Related Overlord RAT samples
  • Associated domains and IP addresses
  • C2 infrastructure
  • WebSocket or WSS connections
  • Persistence mechanisms
  • Suspicious Registry modifications
  • Startup-folder activity
  • Mutex names
  • Related processes and files
  • Previous sandbox executions

threatName:"overlord"

Searching for Overlord RAT in ANY.RUN’s Threat Intelligence Lookup

Searching for Overlord RAT in ANY.RUN’s Threat Intelligence Lookup

Overlord RAT Detection Indicators

Defenders investigating potential Overlord RAT activity can monitor for:

  • Executables using names that resemble legitimate system processes
  • Unexpected copies of executables in user Startup locations
  • New files under unusual AppData directories
  • Registry autorun modifications associated with unknown executables
  • Creation of mutexes using names associated with legitimate Windows components
  • Unexpected WSS/WebSocket connections from suspicious processes
  • Network connections involving ngrok infrastructure
  • Persistent outbound connections from newly executed binaries
  • Suspicious cross-platform RAT agents appearing on organizational endpoints

These behaviors can provide useful detection opportunities even when filenames, hashes, or C2 destinations change.

Overlord RAT Incident Response

If Overlord RAT is identified on an endpoint, organizations should investigate both the malware and the mechanisms used to maintain remote access.

Recommended actions include:

  • Isolate the affected endpoint where appropriate.
  • Preserve relevant forensic evidence before removing artifacts.
  • Identify the original Overlord agent and any copies created during execution.
  • Review Startup-folder contents for suspicious executables.
  • Inspect Registry autorun locations for recently added entries.
  • Investigate suspicious mutex creation and associated processes.
  • Review WSS/WebSocket connections made by the suspected agent.
  • Investigate ngrok-related network activity associated with the compromise.
  • Search other endpoints for matching filenames, paths, registry entries, or behavioral indicators.
  • Review authentication and endpoint telemetry for activity associated with the compromised host.

Because Overlord RAT provides remote access, defenders should also investigate what actions may have been performed while the agent was active.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Overlord RAT is a cross-platform remote access framework built around Go-based agents and a TypeScript/Node/Bun server architecture. Its agents communicate with the C2 infrastructure through encrypted WebSocket connections and can be managed through web or Electron-based interfaces.

The analyzed Windows sample demonstrates several behaviors relevant to defenders, including multiple persistence mechanisms, Windows process masquerading, mutex masquerading, encrypted C2 communication, and ngrok-based tunneling.

Monitoring for suspicious Startup and Registry modifications, unusual AppData executables, masquerading filenames, unexpected WSS connections, and ngrok-related traffic can help organizations identify potential Overlord RAT activity.

Frequently Asked Questions: SmartLoader

1. What is Overlord RAT?

Overlord RAT is a publicly available cross-platform remote access trojan (RAT) framework designed to provide remote access to compromised systems. Its agents are written in Go, while the server component uses TypeScript with Node.js/Bun.

2. Which operating systems does Overlord RAT support?

Overlord RAT supports Windows, Linux, and macOS, allowing the framework to operate across different operating system environments.

3. How does Overlord RAT communicate with its C2 server?

Overlord RAT supports encrypted WebSocket communication using WSS, allowing agents to exchange commands and information with the C2 server.

4. Does Overlord RAT establish persistence?

Yes. Overlord RAT can use persistence mechanisms to help maintain access to compromised systems after the initial execution. The specific mechanisms may vary depending on the platform and implementation.

5. Can Overlord RAT disguise its activity?

Overlord RAT can employ masquerading techniques, such as using filenames or system object names that resemble legitimate components, to make malicious activity less conspicuous.

6. Does Overlord RAT use a mutex?

Overlord RAT can create mutexes as part of its execution. Depending on the implementation, mutex names may also be designed to resemble legitimate system components.

7. Can Overlord RAT use tunneling services for C2?

Overlord RAT can use tunneling services such as ngrok as part of its C2 infrastructure. Such services can provide an intermediary between the agent and remote infrastructure.

8. How can interactive sandboxing and threat intelligence help investigate Overlord RAT?

Interactive sandboxing allows analysts to examine Overlord RAT's execution, persistence, process activity, and network communications.

Threat intelligence can then help connect observed indicators with related samples, infrastructure, and other activity.

HAVE A LOOK AT

Mirage2FA screenshot
Mirage2FA
mirage2fa
Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
Interlock screenshot
Interlock
interlock
Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.
Read More
Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More