logo

Pulsar RAT Attacking Windows Systems via Per-user Run Registry Key and Exfiltrates Sensitive Details

ID: 6b8d5db4-1c2c-5735-92aa-513663e768e1

STIX ID: report--6b8d5db4-1c2c-5735-92aa-513663e768e1

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Pulsar RAT is a Windows-focused remote access trojan that deploys an obfuscated batch and PowerShell-based multi-stage loader, performs in-memory Donut shellcode injection into legitimate processes (e.g., explorer.exe), and establishes persistence via per-user Run registry keys and scheduled tasks. The malware implements extensive anti-analysis controls, steals credentials, wallets, and tokens, and exfiltrates collected data over Discord and Telegram channels; observed command-and-control infrastructure includes 185.132.53.17:7800.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.