CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Abyssos: Technical Analysis of a New Modular RAT

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5794

As cited

Copy frozen at (site build).

threat intel

Abyssos: Technical Analysis of a New Modular RAT

Zscaler ThreatLabz identified Abyssos, a new modular remote administration tool (RAT) written in C++ discovered in late June 2026 that offers credential theft, file exfiltration, virtual network computing (VNC) remote access, and modular plugin capabilities. The malware uses LLVM-based obfuscation including control flow flattening and string encryption, detects virtual machines and analysis tools to evade sandboxes, and communicates with command-and-control (C2) servers using AES-GCM encrypted custom TCP protocols. Abyssos supports extensive post-exploitation commands including keylogging, process management, user account control (UAC) bypass, clipboard interception, and arbitrary code injection, with additional functionality delivered through downloadable modules.

Why it matters: Defenders need to monitor for Abyssos indicators of compromise (IOCs) and behavioral patterns; organizations with exposure to the identified C2 infrastructure (213.145.86.42 and 209.99.184.223) should investigate for active compromises and implement detection rules for the Win64.PWS.Abyssos threat signature.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Abyssos: Technical Analysis of a New Modular RAT

Zscaler ThreatLabz identified Abyssos, a new modular remote administration tool (RAT) written in C++ discovered in late June 2026 that offers credential theft, file exfiltration, virtual network computing (VNC) remote access, and modular plugin capabilities. The malware uses LLVM-based obfuscation including control flow flattening and string encryption, detects virtual machines and analysis tools to evade sandboxes, and communicates with command-and-control (C2) servers using AES-GCM encrypted custom TCP protocols. Abyssos supports extensive post-exploitation commands including keylogging, process management, user account control (UAC) bypass, clipboard interception, and arbitrary code injection, with additional functionality delivered through downloadable modules.

Why it matters: Defenders need to monitor for Abyssos indicators of compromise (IOCs) and behavioral patterns; organizations with exposure to the identified C2 infrastructure (213.145.86.42 and 209.99.184.223) should investigate for active compromises and implement detection rules for the Win64.PWS.Abyssos threat signature.

VendorsMicrosoftGoogleVMware
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary