August 2026 saw coordinated attacks targeting US and EU businesses through session hijacking, RMM abuse, and insider threats. Threat actors leveraged legitimate tools and authentication flows to bypass MFA, steal active sessions, and establish persistent remote access. Campaigns like Mirage2FA and 3DBlast targeted Microsoft 365 and Google login flows, while SnakeBiteAgent delivered full remote access capabilities via business-themed archives.
RAT
22 posts
Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk Carry-On Compromise: TA4922 Packs PackClient Proofpoint identified PackClient, a modular RAT and C2 framework marketed on Telegram and used by TA4922 in tax-themed phishing campaigns targeting organizations in China and India between May and July 2026. The malware employs a multi-stage loading chain with reflective DLL loading, registry-based persistence, and a custom TCP C2 protocol on port 6666. PackClient supports over 60 commands and a plugin system enabling keylogging, screen capture, proxy tunneling, webcam access, and potential Telegram traffic interception.
CNCMachineRMS C2 Protocol CNCMachineRMS is a remote access trojan using a custom binary C2 protocol over TCP port 443 without TLS. It leverages DNS over HTTPS (DoH) to resolve C2 domains, bypassing local DNS logging. The protocol is identifiable by statistical analysis due to distinctive byte patterns at fixed offsets. Delivery has been observed via ClickFix attacks delivering the BabaDeda chain.
Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers July 2026 saw coordinated phishing and malware campaigns targeting US, European, and Brazilian organizations through abuse of trusted business platforms and legitimate authentication flows. Key threats include Kratos and Kali365 phishing-as-a-service operations targeting Microsoft 365 accounts via credential theft and device code phishing, multiple stealer/RAT families (DestinyStealer, DARTHVADER, Banana RAT, OVERLORD RAT) collecting broad credential and session data, and PhantomEnigma's abuse of compromised Brazilian government infrastructure for malware delivery. Attackers consistently used legitimate tools and rotating infrastructure to evade indicator-based defenses.
Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers Attackers distributed malicious functionality across a cluster of npm packages that impersonate private Alibaba (@ali scope) packages, triggering a multi-stage download chain that ultimately deploys a cross-platform RAT named aone-cli. The malware employs a Node.js vm sandbox-escape technique to gain process-level access, uses Alibaba Cloud OSS and a compromised GitHub repository to blend malicious traffic with legitimate infrastructure, and establishes persistence via shell profile modification, Launch Agents, code injection into AI tooling, and replacement of a legitimate security application's core code on Windows.
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration The GoSerpent campaign is a sophisticated, multi-stage attack targeting government and diplomatic entities in Southeast Asia since at least 2021, with evolved variants deployed through 2026. The Go-based GoSerpent backdoor establishes persistent access and deploys ThumbcacheService for document collection, Mimikatz and QuarksDumpLocalHash for credential dumping, and later stages use Stowaway RAT and TmcLoader/TmcPayload to exfiltrate collected data via network shares using stolen credentials. The tight integration between collection, credential theft, and exfiltration components demonstrates advanced operational planning and long-term intelligence gathering objectives.
From Fake Amazon Security Alert to HarborWatch Agent: ClickFix Delivery of a Custom Monitoring RAT A recent phishing campaign impersonates Amazon security alerts to deliver a custom remote access trojan (RAT) dubbed HarborWatch Agent. The attack leverages the ClickFix technique, using a fake CAPTCHA page to socially engineer victims into manually executing a malicious PowerShell command via the Windows Run dialog. Once executed, the script downloads the RAT, which collects system information and communicates with a C2 infrastructure managed via a panel called Harbor Sentinel.
Argamal: Malware hidden in hentai games A newly discovered malware campaign dubbed Argamal targets users downloading adult games, utilizing DLL sideloading and COM hijacking to deploy a sophisticated Remote Access Trojan (RAT). The malware establishes persistence by hijacking the Windows Color System Calibration Loader and grants attackers full system control, including surveillance, file exfiltration, and arbitrary command execution.
From Fake Purchase Orders to Remote Access: Analyzing the JS.MonoGlyphRAT Threat to US Enterprises JS.MonoGlyphRAT is a newly identified, highly obfuscated JavaScript backdoor targeting US enterprises via phishing. It establishes persistence, communicates over HTTP using custom headers, and acts as a loader capable of executing AES-encrypted payloads, PowerShell commands, and in-memory .NET assemblies while bypassing AMSI.
Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years A cybercrime campaign is targeting users of pirated media sites with a fake video player update that deploys a modified SilentCryptoMiner and a Remote Access Trojan (RAT). The malware utilizes DLL side-loading, DNS tunneling for initial check-ins, and a DGA for C2 communications, while employing a Watchdog component to ensure persistence via a rogue Google Update service.
That AI Extension Helping You Write Emails? It’s Reading Them First Unit 42 identified 18 high-risk browser extensions masquerading as GenAI productivity tools that function as remote access Trojans, infostealers, and spyware. These extensions exploit browser permissions to intercept API keys, exfiltrate DOM content, establish persistent WebSocket C2 channels, and dynamically route traffic via malicious proxy configurations.
Weaponizing Apathy: How Threat Actors Exploit Vulnerabilities and Legitimate Software Threat actors are increasingly weaponizing legitimate software and known vulnerabilities to bypass endpoint detection and response (EDR) systems. Between December 2021 and December 2024, the abuse of legitimate Remote Access Tools (RATs) like NetSupport Manager and ConnectWise has surged, often delivered via phishing emails exploiting older Microsoft Office vulnerabilities to establish persistent, stealthy access.
Supply Chain Compromise Impacts Axios Node Package Manager A software supply chain compromise impacted the Axios npm package, injecting a malicious dependency ([email protected]) into versions 1.14.1 and 0.30.4. This dependency downloads multi-stage payloads, including a Remote Access Trojan (RAT), which communicates with a known malicious C2 domain.
North Korea’s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads North Korea's Contagious Interview campaign has launched a coordinated supply chain attack across five major open-source ecosystems. The threat actors published malicious packages masquerading as legitimate developer tools that act as staged loaders to deliver remote access trojans (RATs) and infostealers to developer workstations.
Intelligence Center A critical supply chain attack compromised the official Axios npm package, deploying malicious versions v1.14.1 and v0.30.4. The packages contained a fake runtime dependency that automatically executed post-install, downloading platform-specific Remote Access Trojans (RATs) to Windows, MacOS, and Linux systems to facilitate credential exfiltration and remote access.
Supply Chain Attack on Axios Pulls Malicious Dependency from npm A critical supply chain attack compromised the widely used Axios npm package, publishing malicious versions that introduced a trojanized dependency. This dependency executes a multi-stage remote access trojan (RAT) across Windows, macOS, and Linux systems, utilizing obfuscation and anti-forensics to evade detection and establish persistence.
Mitigating the Axios npm supply chain compromise On March 31, 2026, the popular Axios npm package was compromised in a supply chain attack attributed to North Korean threat actor Sapphire Sleet. Malicious versions 1.14.1 and 0.30.4 included a fake dependency that silently executed a post-install script to download and install OS-specific Remote Access Trojans (RATs) on Windows, macOS, and Linux systems.
Elastic releases detections for the Axios supply chain compromise A critical supply chain attack compromised the popular Axios npm package, utilizing a malicious transitive dependency to execute cross-platform payloads during installation. The attack targets Linux, Windows, and macOS systems, deploying OS-specific Remote Access Trojans (RATs) capable of host profiling, command execution, and follow-on payload delivery. Detection engineering efforts should focus on anomalous process ancestry, such as Node.js spawning native OS shells to retrieve and background remote payloads.
Axios npm package compromised to deploy malware A supply chain attack compromised the widely used Axios npm package (versions 1.14.1 and 0.30.4) following a maintainer account takeover. The malicious packages deploy a cross-platform remote access trojan (RAT) during installation, which fetches second-stage payloads and actively evades forensic detection by cleaning up artifacts and altering package metadata.
Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads The highly popular Axios npm package was compromised when an attacker hijacked a lead maintainer's account to publish malicious versions. These versions included a phantom dependency that deployed a cross-platform Remote Access Trojan (RAT) via a postinstall hook, utilizing advanced obfuscation and anti-forensic techniques to hide its presence. The attack highlights critical risks in the software supply chain, specifically regarding dependency resolution and CI/CD pipeline protections.
The Telnyx PyPI Compromise and the 2026 TeamPCP Supply Chain Attacks Threat actor TeamPCP orchestrated a cascading supply chain attack by exploiting a misconfigured GitHub Actions workflow in Aqua Security's Trivy, harvesting credentials to compromise subsequent repositories including Checkmarx, LiteLLM, and Telnyx. The malicious packages deploy sophisticated, OS-specific remote access trojans (RATs) that utilize steganography, process hollowing, and ETW patching to evade detection while exfiltrating sensitive data.
Abusing Windows File Explorer and WebDAV for Malware Delivery Threat actors are leveraging WebDAV and Windows File Explorer to deliver Remote Access Trojans (RATs) while bypassing traditional web browser security controls. By utilizing .url and .lnk shortcut files pointing to WebDAV servers hosted on temporary Cloudflare Tunnels, attackers can trick users into executing malicious scripts that appear as local files.