Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantdefense-evasion-methodcommand-and-control-methodcredential-access-method

New Remote Access Trojans Expand Stealth and Surveillance Capabilities

Updated 3mo agoFirst seen Feb 21, 20264 sources

Threat researchers reported multiple remote access trojan (RAT) developments that emphasize stealth, surveillance, and post-exploitation flexibility. A new Remcos RAT variant was observed adding real-time surveillance features (including on-demand webcam streaming) and keystroke transmission, while improving evasion through modular DLL plugins, encrypted C2 with in-memory-only config decryption, and dynamic API resolution; it also attempts to reduce forensic artifacts by deleting collected data (e.g., screenshots, audio, keylogging output, cookies) and removing persistence-related registry entries.

Separately, Elastic detailed a ClickFix social-engineering campaign that uses compromised legitimate websites as delivery infrastructure to deploy a previously undocumented Windows RAT dubbed MIMICRAT (AstarionRAT). The intrusion chain includes a multi-stage PowerShell flow with ETW and AMSI bypass, a Lua-based shellcode loader, and HTTPS C2 on port 443 using traffic patterns designed to resemble web analytics; the implant supports token impersonation, SOCKS5 tunneling, and a broad command set, with suspected end goals of ransomware deployment or data theft. In parallel mobile-focused reporting, Zimperium described ZeroDayRAT, a cross-platform Android/iOS spyware-style RAT distributed via social engineering and sideloaded apps, enabling screen capture, keylogging, and credential/file exfiltration, highlighting continued convergence of surveillance and remote-control capabilities across endpoints.

Share:
New Remote Access Trojans Expand Stealth and Surveillance Capabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 20, 20264mo ago

Researchers report enhanced surveillance features in new Remcos RAT variant

Point Wild's Lat61 Threat Intelligence Team reported a new Remcos RAT variant with expanded surveillance features such as real-time keystroke transmission and live webcam streaming. The variant also adds stealth improvements including modular DLL plugins, encrypted C2, in-memory decryption, dynamic API resolution, and artifact cleanup.

Elastic discloses ClickFix campaign delivering newly documented MIMICRAT

Elastic Security Labs disclosed a ClickFix campaign using compromised legitimate websites, including bincheck[.]io, to deliver a previously undocumented RAT called MIMICRAT, also known as AstarionRAT. The infection chain uses fake Cloudflare verification prompts and multi-stage PowerShell, Lua, and shellcode components to install a C++ implant designed for stealthy post-exploitation.

Feb 19, 20264mo ago

Researchers identify ZeroDayRAT mobile spyware targeting Android and iOS

Zimperium researchers reported a new cross-platform mobile remote access trojan called ZeroDayRAT that targets both Android and iOS devices. The malware is described as being spread through social-engineering lures and sideloaded apps, with capabilities including screen capture, keylogging, and theft of files and credentials.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Affected products
7 linked
AndroidAndroidIosIosWindowsCloudflarePowershell
Organizations
4 linked
ElasticCloudflareHuntressBincheck
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

New Remote Access Trojans Expand Stealth and Surveillance Capabilities | Mallory