logo

SpankRAT Exploits Windows Explorer Processes for Stealth and Delayed Detection

ID: b94c9821-4e18-504b-90c1-434689369ed4

STIX ID: report--b94c9821-4e18-504b-90c1-434689369ed4

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-21

Author: Balaji N

...
...

SpankRAT is a stealthy two-component Rust Remote Access Trojan that abuses legitimate Windows processes (injecting rmm_agent.dll into explorer.exe) to mask C2 traffic over WebSockets, persist via a high-privilege Scheduled Task (RmmAgentCore), and provide a broad set of remote control capabilities; investigators provide IOCs (C2 IPs, file names, agent hash, drop path) and warn that samples were largely undetected on VirusTotal, highlighting the need for behavioral and sandbox analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.