New STX RAT Uses Hidden Remote Desktop and Infostealer Features to Evade Detection
ID: 4a96b5d7-24b6-5558-ae46-de7530569d98
STIX ID: report--4a96b5d7-24b6-5558-ae46-de7530569d98
Feed Name: cybersecurityNews.com
A newly discovered remote access trojan named STX RAT (observed Feb–Mar 2026) provides stealthy hidden remote desktop control (HVNC), credential theft targeting FTP/SFTP clients, and strong ECDH/ChaCha20-Poly1305 encrypted C2 communications. The malware uses multi-stage delivery (browser-downloaded VBScript → JScript → TAR → PowerShell loader or trojanized installers), advanced anti-analysis (VM checks, AMSI-ghosting), and has been observed contacting C2 95.216.51.236; eSentire recommends blocking the C2, deploying YARA rules, and monitoring for suspicious WScript/PowerShell activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
