logo

DesckVB RAT Uses Obfuscated JavaScript and Fileless .NET Loader to Evade Detection

ID: cfd76493-7b20-5bbf-acb5-52f396889bda

STIX ID: report--cfd76493-7b20-5bbf-acb5-52f396889bda

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

This report analyzes DesckVB RAT, a 2026-era fileless Remote Access Trojan that uses heavily obfuscated JavaScript and PowerShell to load .NET assemblies directly into memory via reflection and process injection. It documents capabilities including keylogging, webcam access, AV-evasion and encrypted C2 communications, and provides IOCs (manikandan83.mysynology.net, 45.156.87.226:7535) and behavioral indicators (use of InstallUtil.exe, scripts dropped to C:\Users\Public), with recommended detection and mitigation steps such as blocking script execution, enabling detailed PowerShell logging, and keeping endpoint protection up to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.