logo

Hackers Attacking IT & OSINT Professionals with New PyStoreRAT to Gain Remote Access

ID: 002eae8a-f06f-555f-83c2-ef160814fab4

STIX ID: report--002eae8a-f06f-555f-83c2-ef160814fab4

Feed Name: cybersecurityNews.com

Threat Score
82/100

Date Published: 2026-02-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A sophisticated supply-chain campaign is reactivating dormant GitHub accounts to publish AI-generated projects that later receive malicious maintenance commits installing a backdoor called PyStoreRAT; the loader profiles victims, deploys payloads including the Rhadamanthys stealer, spreads via removable drives, adapts execution to avoid AVs, and uses resilient rotating C2 nodes — targeting IT administrators and OSINT professionals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.