Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

SolarisLoader

60
Global rank
52 infographic chevron month
Month rank
39 infographic chevron week
Week rank

SolarisLoader is a malware loader designed to neutralize security infrastructure before deploying high-risk secondary payloads. It utilizes a "Bring Your Own Vulnerable Driver" technique to gain kernel-level access and terminate antivirus processes. To remain undetected, the malware patches internal Windows monitoring interfaces and isolates the machine from security updates. Finally, it establishes a resilient three-layer persistence mechanism involving scheduled tasks, registry backups, and a watchdog component.

Loader
Type
Unknown
Origin
1 June, 2026
First seen
25 September, 2026
Last seen

How to analyze SolarisLoader with ANY.RUN

Type
Unknown
Origin
1 June, 2026
First seen
25 September, 2026
Last seen

IOCs

IP addresses
74.178.240.61
2.23.246.9
2.16.241.7
48.209.133.15
88.221.169.152
57.153.246.3
23.52.181.212
23.3.89.90
48.209.138.189
23.11.41.157
20.165.94.54
128.24.231.64
193.178.158.107
48.209.138.168
40.126.31.69
172.211.123.248
142.251.151.119
199.151.19.104
210.149.248.21
217.186.228.201
Hashes
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
31d04c1e4bfdfa34704c142fa98f80c0a3076e4b312d6ada57c4be9d9c7dcf26
303ec5f3f084e0eabb7d9210c4a58e878cbf42fc7bc6a6222d9fd163e78d2263
3a543afcb9904e72b9d1408ae233e7452be0ff29721f43dff5854440961bd820
cad0f7845e7587496fd1d23d20661451496ebe4da3167c9bb1b1615b78d55cab
50ec3f4ae2020f9c87685bb77a9c688f3c5d0fb93d26478349cb5a4282cac66d
8888ef5801968a73cf5848ca974da5bfb2a2e9e08bf2b1222d0dc09b78643f05
85a2093946270494a6b78cc388a7927126474b82eb054f8ed6cd3be51ea7f275
b67ae6dea2a11ce75ff820029fbaf0911fb343068e068ee007374bcfddb6edb8
f7e4aae30ab2bda60bead5fd5a29a36685d768df007d3399d3047768babae200
83b3fb548b094aa66bbf9da57c4d5a49acaa76914121e90aa05fb53ab47367e0
c0b6ac8c1df175e2e1df3f1a73bb4e2a4594bf6108146d7dd986cd70cb68e974
64dcbddf381aa27bc7bbc0ec07fb01636d49e9d31acfaab1fa918029d84ecd0a
785e2dda4c552619064b7ace8222eef182a40d8972556444d0019dd97001ff47
214243da6db82fdf058906341a90c0bdb2976bc3a4e9f4d444872e0dc1b5449e
5fe73d34592af04bc8e2e6182afd72c1f4698da7392ff13352468a86bc3432ac
8f0ae8906644dcb0b935b1bdec5dc4dedfece1656e041651649608cdcfb78084
efbdbbcd0d954f8fdc53467de5d89ad525e4e4a9cfff8a15d07c6fdb350c407f
6823b98c3e922490a2f97f54862d32193900077e49f0360522b19e06e6da24b4
d3acd72f585872f36d7329faf6146dc2d71c3cbcbd58d94e36da285738adaa68
Domains
www.microsoft.com
ecs.office.com
activation-v2.sls.microsoft.com
slscr.update.microsoft.com
crl.microsoft.com
go.microsoft.com
settings-win.data.microsoft.com
www.google.com
google.com
www.bing.com
client.wns.windows.com
self.events.data.microsoft.com
ocsp.digicert.com
fe3cr.delivery.mp.microsoft.com
login.live.com
pgo.fatherchrismas.com
documents-elegant.at.ply.gg
cfs5.tistory.com
pastebin.com
shadowroute.io
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://www.google.com/
http://www.bing.com/
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://193.178.158.107/login.php
http://193.178.158.107//uploads/5ad07daa60a8a515_101.php
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://193.178.158.107//uploads/f9fb5f6633503441_101.php
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
Last Seen at
Last Seen at

Recent blog posts

post image
ANY.RUN at RootedCON Valencia 2026: Where Cyb...
watchers 2278
comments 0
post image
Phishing Risk Across 5 Key US Industries: ANY...
watchers 7064
comments 0
post image
CSuite Targets US and EU Organizations with D...
watchers 13219
comments 0

Key Takeaways

  • Kernel-Level Defense Dismantling: SolarisLoader utilizes a "Bring Your Own Vulnerable Driver" (BYOVD) technique, exploiting a vulnerable Safetica endpoint protection driver (CVE-2026-0828) to gain kernel-level access and forcibly terminate security processes.
  • Telemetry Blinding: The malware prevents the operating system from logging or reporting malicious activity by patching the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) in memory via direct opcode modification.
  • Resilient Triple-Layer Persistence: The infection survives standard cleanup through a combination of scheduled tasks, registry-backed backups (ICtrlData), and a watchdog process that injects code into legitimate system files like RuntimeBroker.exe.
  • ANY.RUN’s Interactive Sandbox analysis confirms that the loader utilizes a silent COM-elevation/UAC-bypass path via dllhost.exe, enabling it to gain administrative privileges without triggering user-facing notifications or consent prompts.

ANY.RUN detects SolarisLoader fast, providing a response-ready report for SOC teams ANY.RUN detects SolarisLoader fast, providing a response-ready report for SOC teams

  • Active Malware-as-a-Service (MaaS) Cycle: The loader is in active development, functioning as a primary delivery vehicle for secondary payloads such as StealC, Amadey, and REMCOS RAT.

What is SolarisLoader?

SolarisLoader is a sophisticated Malware-as-a-Service (MaaS) delivery vehicle designed to dismantle a system's security infrastructure before deploying high-risk secondary payloads. First identified in early 2026, the malware is characterized by its aggressive approach to antivirus software: rather than merely attempting to hide, it actively seeks and destroys security processes from the kernel level. While it does not typically steal data itself, it creates a "blind spot" on the infected host, clearing the way for infamous stealers and loaders like Amadey.

The malware is primarily distributed through fake software installers bundled with cracked or pirated versions of popular applications and games. This distribution strategy exploits users who are already attempting to bypass legitimate software protocols, making them less likely to question the silent background installations or administrative requests that occur during the infection chain. In some instances, the loader will even drop and execute the legitimate cracked software after the infection is complete to further reduce user suspicion.

Technical analysis reveals that SolarisLoader is a highly professional product undergoing rapid evolution. Since its emergence, researchers have tracked its maturation from version 1.2.0 to 1.8.2, observing iterative refinements in its C2 communication protocols, anti-analysis techniques, and persistence mechanisms. Its core design prioritizes persistence and stealth; it utilizes a dedicated watchdog component (often recovered via PDB paths as "Solaris") that monitors the system and automatically re-initiates the malware implant if it is terminated or deleted. By combining kernel-level exploits with telemetry patching, SolarisLoader ensures that a compromised system's own security stack reports nothing unusual even as secondary payloads are actively executed.

How SolarisLoader Threatens Businesses and Organizations

For modern enterprises, SolarisLoader’s primary threat lies in its ability to create a "permanent blind spot" on an infected workstation, ensuring that subsequent malicious activities go entirely undetected by traditional monitoring tools.

Unlike most loaders that attempt to hide from security software, SolarisLoader uses a "Bring Your Own Vulnerable Driver" (BYOVD) technique to gain kernel-level access. By exploiting CVE-2026-0828 in the Safetica endpoint protection driver, the malware achieves the same system privileges as the security software itself, allowing it to forcibly terminate Windows Defender and major third-party antivirus processes like Avast, AVG, and 360 Total Security. The malware systematically "blinds" the operating system by patching the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) directly in memory. This ensures that even if follow-on payloads execute suspicious scripts or file operations, the OS will not generate the event logs or telemetry needed for EDR (Endpoint Detection and Response) or SOC teams to flag the intrusion.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

The targeting profile of SolarisLoader is opportunistic and designed to exploit gaps in both technical controls and user behavior. While its distribution is global, specific technical markers reveal focused targeting strategies:

TI Lookup shows all the latest threat intel on Solaris Loader TI Lookup shows all the latest threat intel on Solaris Loader

  • US and EU Companies: According to ANY.RUN’s [Threat Intelligence Lookup], the majority of Solaris Loader attacks affected businesses from the United States and the European Union.
  • Organizations with Permissive Local Admin Rights: SolarisLoader relies on gaining administrative privileges to execute its most damaging stages, such as driver loading and hosts file modification. It utilizes a silent COM-elevation/UAC-bypass path via dllhost.exe, which means users running with local administrative rights can be compromised without ever seeing a permission prompt.
  • Global Enterprise Users: The malware's targeting of global suites like Avast, AVG, and ReasonLabs makes it a universal threat. Any organization relying solely on signature-based antivirus or standard Windows telemetry (AMSI/ETW) is highly vulnerable, as SolarisLoader's telemetry-blinding and BYOVD techniques are specifically designed to defeat these common defenses.
  • Secondary Infection Targets: Systems already compromised by other loaders, such as XTinyLoader or Amadey, are frequently targeted for SolarisLoader deployment, as it is often used as an intermediate stage to clear security hurdles before a final payload is delivered.

How Does SolarisLoader Function?

Detonating a SolarisLoader sample inside ANY.RUN’s Interactive Sandbox reveals a highly aggressive and multi-staged attack chain designed to neutralize system defenses before establishing a permanent foothold. By moving beyond simple file execution, the loader utilizes a series of strategic maneuvers to blind the operating system and deliver high-risk secondary payloads.

Stage 1: Initial Execution and Silent Elevation

The infection typically begins when the user executes a malicious installer, which runs from the user's Temp directory. Upon launch, the malware drops several staged components into the %TEMP% folder, including WinSysKdrv.exe, 0_1671390.exe, and 1_1675328.exe. SolarisLoader detonated inside ANY.RUN’s Interactive Sandbox SolarisLoader detonated inside ANY.RUN’s Interactive Sandbox

To gain the administrative privileges necessary for its subsequent stages without alerting the user, the loader spawns WinSysKdrv.exe through dllhost.exe (COM surrogate), a technique consistent with a silent COM-elevation/UAC-bypass path. Early in this execution phase, the sample creates the SOLARIS mutex, which acts as both an execution guard and an infection marker on the host to prevent multiple instances from running simultaneously.

SolarisLoader mutex detected by ANY.RUN’s Interactive Sandbox SolarisLoader mutex detected by ANY.RUN’s Interactive Sandbox

Stage 2: Defense Dismantling and Network Isolation

Once elevated, SolarisLoader immediately begins systematically dismantling the endpoint's security stack. The sandbox analysis highlights several critical actions:

  • Neutralizing Windows Defender: The malware disables real-time protection and modifies registry values associated with security policies and exclusion lists to prevent detection.

SolarisLoader disables MS Defender SolarisLoader disables MS Defender

  • Kernel-Level Tampering: The loader creates or modifies Windows services specifically tied to kernel-driver loading. This allows the malware to achieve defense evasion by operating at the same privilege level as the operating system's core.
  • Network Isolation: To prevent the machine from receiving updates or communicating with security telemetry servers, the malware rewrites the Windows hosts file. It redirects critical security and telemetry domains to unreachable local addresses, effectively isolating the host from external remediation.
Stage 3: Resilient Persistence and Watchdog Behavior

SolarisLoader injects itself into a legitimate process SolarisLoader injects itself into a legitimate process

SolarisLoader is engineered for maximum resilience against manual or automated cleanup. It ensures survival through two primary mechanisms:

  • Process Injection: The malware injects malicious code into legitimate system processes, specifically RuntimeBroker.exe and sihost.exe. This acts as a watchdog, where these trusted system components monitor the infection and can re-initiate the malware if it is interrupted.
  • Registry-Based Fallback: For long-term survival, it sets a login/logoff helper path in the registry as a fallback mechanism, ensuring the loader re-executes whenever a user logs into the system.

Logon-script persistence fallback via the registry Logon-script persistence fallback via the registry

Stage 4: Host Reconnaissance (Fingerprinting)

Before contacting its command-and-control (C2) infrastructure, SolarisLoader performs a thorough reconnaissance of the infected workstation to create a unique host fingerprint.

Host fingerprinting: computer name, machine GUID, languages, install date, location Host fingerprinting: computer name, machine GUID, languages, install date, location

The sandbox observed the malware harvesting the following data points: Computer name and machine GUID, Windows installation date and system location settings, Supported system languages.

Stage 5: C2 Communication and Payload Delivery

The final stage of the attack involves establishing communication with the attacker's infrastructure to fulfill its role as a loader. The sample beacons to a specific C2 endpoint at 196[.]251[.]107[.]186/api.php.

SolarisLoader’s C2 beacon SolarisLoader’s C2 beacon

Following this check-in, the loader was observed pulling additional malicious payloads, including bot_x64.exe and klr.exe, from a secondary IP address (192[.]162[.]199[.]186) that has been flagged as malicious. This confirms that SolarisLoader's ultimate goal is to serve as a delivery vehicle for further staged malicious activity.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against Solaris

Because SolarisLoader operates as an evolving Malware-as-a-Service (MaaS) with infrastructure and file names that rotate rapidly, traditional static blocklists are often insufficient for long-term protection. Security teams must shift from tracking temporary indicators to identifying the durable technical fingerprints and behavioral patterns of the operation. By leveraging ANY.RUN’s Threat Intelligence, organizations can stay ahead of these evolving campaigns.

Threat Intelligence Lookup allows analysts to pivot from a single suspicious artifact to an entire cluster of related malicious activity.

threatName:"solaris"

Threat Intelligence Lookup provides actionable SolarisLoader indicators and TTPs Threat Intelligence Lookup provides actionable SolarisLoader indicators and TTPs

TI Lookup delivers a complete context on the threat, providing rich intelligence on SolarisLoader attacks, including network indicators, mutexes, file names, as well as full sandbox sessions that demonstrate the entire execution cycle from start to finish. For organizations requiring automated, high-speed protection, ANY.RUN’s Threat Intelligence Feeds provide a real-time stream of validated indicators. These feeds deliver a continuous flow of the latest C2 domains and malicious IPs directly into SIEM, SOAR, and EDR platforms. By integrating these feeds, teams can automatically block emerging malicious infrastructure, such as rotating fake-installer portals, and detect active breaches before data exfiltration occurs.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

SolarisLoader represents a strategic shift in the cybercrime landscape, moving beyond simple evasion to the systematic neutralization of the entire security stack. By combining kernel-level exploits with telemetry blinding, the malware creates an environment where secondary payloads can operate with total visibility while the operating system remains unaware of the intrusion. To combat this evolving threat, organizations must move beyond static blocklists and reactive defenses, adopting a strategy that prioritizes behavioral analysis and proactive threat intelligence. Utilizing interactive sandboxing is essential to deobfuscate the loader's multi-stage logic and identify the durable technical signals, such as unauthorized driver loading and system-level telemetry tampering, before the successful delivery of high-risk secondary infections.

Frequently Asked Questions: SolarisLoader

1. What is SolarisLoader?

SolarisLoader is a specialized malware delivery vehicle designed to gain a persistent foothold on a host, disable its security tools, and deliver secondary infections like stealers and remote access trojans. It is sold on a subscription basis, allowing various threat actors to deploy it as a primary entry point for broader campaigns.

2. How does SolarisLoader bypass traditional security software?

The malware utilizes a "Bring Your Own Vulnerable Driver" (BYOVD) technique, exploiting a documented vulnerability in a legitimate third-party driver to achieve kernel-level privileges. This gives the loader the same system permissions as the security software it is attacking, allowing it to forcibly terminate security processes and endpoint detection services.

3. Why is a "clean" security scan result not trustworthy if this malware is present?

SolarisLoader specifically patches internal monitoring interfaces, such as the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW), in memory. This "blinds" the system’s own telemetry, preventing it from logging or reporting malicious activity even if the security software remains active.

4. How can organizations use interactive sandboxing and threat intelligence to stay protected?

Interactive sandboxing is essential to expose the modular logic that evades automated scanners, allowing defenders to see how the malware escalates privileges and dismantles defenses in real-time. Proactive threat intelligence allows teams to identify stable build-chain fingerprints and block rotating C2 infrastructure before it reaches the endpoint.

5. What are the key indicators of a SolarisLoader infection?

Defenders should monitor for unauthorized redirects in the system hosts file (pointing security domains to unroutable addresses), the creation of scheduled tasks disguised as system security checks, and unauthorized additions to security exclusion lists. The presence of specific binary data in the system registry also serves as a backup for the malware's self-healing loop.

HAVE A LOOK AT

INC Ransomware screenshot
INC Ransomware is a ransomware-as-a-service (RaaS) spotted in mid-2023. It targets industries like retail, real estate, finance, healthcare, and education, primarily in the U.S. and UK. It encrypts and exfiltrates data demanding a ransom. It employs advanced evasion techniques, destroys backup, and abuses legitimate system tools at all the stages of the kill chain.
Read More
Oyster screenshot
Oyster
oyster
Oyster (also seen in reporting as Broomstick or CleanUpLoader) is a Windows backdoor/loader actively used in multi-stage intrusion campaigns. Recent campaigns weaponize SEO-poisoning and malvertising to trick IT and dev users into downloading trojanized installers (PuTTY, WinSCP, Microsoft Teams, etc.), which then drop Oyster to establish a persistent foothold and load additional payloads (often leading to data theft or ransomware).
Read More
Wshrat screenshot
Wshrat
wshrat rat trojan
WSHRAT is a Remote Access Trojan — a malware that allows the attackers to take over the infected machines. The RAT has been in circulation since 2013 and it is arguably most notable for the numerous versions released into the wild.
Read More
Quasar RAT screenshot
Quasar RAT
quasar trojan rat
Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.
Read More
LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More