Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Abyssos: Technical Analysis of a New Modular RAT

ca94d95413210a2a325155740eb8a5c58627ad5c4e704478621e7fc8165fe173

TLP:CLEAR
Active

SHA-256 Hash

Description

In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Abyssos: Technical Analysis of a New Modular RAT
Pattern Type
STIX
Confidence
75%
Valid From
Aug 11, 2026 12:00
Total Sightings
0
Added
Aug 11, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of ca94d95413210a2a325155740eb8a5c58627ad5c4e704478621e7fc8165fe173

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.