logo

Pulsar RAT Using Memory-Only Execution & HVNC to Gain Invisible Remote Access

ID: 44764b2f-3ef2-5c18-911e-c670af984b50

STIX ID: report--44764b2f-3ef2-5c18-911e-c670af984b50

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-20

Date Updated: 2026-04-21

Author: Abinaya

...
...

Pulsar RAT is a sophisticated, fileless Windows remote access trojan descended from Quasar that uses memory-only execution, HVNC, anti-VM/debugging, UAC bypass, scheduled-task persistence, credential theft (Kematian Grabber), keylogging, clipboard hijacking, and modular plugins; recent campaigns distributed it via compromised supply-chain (malicious npm packages) and multi-RAT drops, posing a high operational impact and requiring layered detection and response measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.