started · updated
Malware activity surges as remote access trojans and stealthy script chains increase
Global malware activity has seen a significant increase in remote access trojans (RATs), information stealers, and loaders. AsyncRAT remains a dominant threat with 211 weekly sample uploads, often delivered via phishing and utilizing trusted cloud infrastructure like Cloudflare to evade detection. Remcos RAT has also seen a sharp rise in activity, with newer variants focusing on real-time surveillance, such as live webcam streaming and instant keystroke transmission.
In a separate but related trend of sophisticated delivery, a new campaign is utilizing Visual Basic Script (VBS) and PowerShell to deploy RAT chains. This method uses DuckDNS hosts to distribute malicious scripts that appear as legitimate Windows activity. The attack chain employs AES-256 encryption and process hollowing—a technique where malicious code is injected into a legitimate process—to bypass security defenses and steal browser data, keystrokes, and clipboard contents.
Entities
AsyncRAT · Cloudflare · DuckDNS · Remcos RAT · Xworm