As cited
Copy frozen at (site build).
threat intel
Abyssos: Technical Analysis of a New Modular RAT
Zscaler ThreatLabz identified Abyssos, a new modular remote administration tool (RAT) written in C++ discovered in late June 2026 that offers credential theft, file exfiltration, virtual network computing (VNC) remote access, and modular plugin capabilities. The malware uses LLVM-based obfuscation including control flow flattening and string encryption, detects virtual machines and analysis tools to evade sandboxes, and communicates with command-and-control (C2) servers using AES-GCM encrypted custom TCP protocols. Abyssos supports extensive post-exploitation commands including keylogging, process management, user account control (UAC) bypass, clipboard interception, and arbitrary code injection, with additional functionality delivered through downloadable modules.
Why it matters: Defenders need to monitor for Abyssos indicators of compromise (IOCs) and behavioral patterns; organizations with exposure to the identified C2 infrastructure (213.145.86.42 and 209.99.184.223) should investigate for active compromises and implement detection rules for the Win64.PWS.Abyssos threat signature.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Abyssos: Technical Analysis of a New Modular RAT
Zscaler ThreatLabz identified Abyssos, a new modular remote administration tool (RAT) written in C++ discovered in late June 2026 that offers credential theft, file exfiltration, virtual network computing (VNC) remote access, and modular plugin capabilities. The malware uses LLVM-based obfuscation including control flow flattening and string encryption, detects virtual machines and analysis tools to evade sandboxes, and communicates with command-and-control (C2) servers using AES-GCM encrypted custom TCP protocols. Abyssos supports extensive post-exploitation commands including keylogging, process management, user account control (UAC) bypass, clipboard interception, and arbitrary code injection, with additional functionality delivered through downloadable modules.
Why it matters: Defenders need to monitor for Abyssos indicators of compromise (IOCs) and behavioral patterns; organizations with exposure to the identified C2 infrastructure (213.145.86.42 and 209.99.184.223) should investigate for active compromises and implement detection rules for the Win64.PWS.Abyssos threat signature.
- Source published
- First seen by Cybersecurity Tracker