Abyssos is a modular remote administration tool written in C++ identified by Zscaler ThreatLabz in late June 2026. It uses LLVM-based obfuscation, anti-analysis checks, and a custom AES-GCM encrypted TCP protocol for C2 communication. The RAT supports a wide range of capabilities including VNC, keylogging, clipboard interception, file exfiltration, process management, UAC bypass, browser session hijacking, and a modular plugin system for credential harvesting and network scanning.
browser-hijacking
2 posts
Abyssos Modular RAT Analysis | ThreatLabz The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version XCSSET v40 is a modular macOS malware targeting software developers through infected Xcode projects. It features advanced stealth techniques including fileless persistence via the macOS defaults system, multi-layered polymorphism, and active impairment of macOS security mechanisms like XProtect and TCC. New operational modules include a Chrome DevTools Protocol (CDP) hijacker for browser manipulation and a Telegram trojanizer for persistent access.