DesckVB RAT Uses Obfuscated JavaScript and Fileless .NET Loader to Evade Detection
ID: cfd76493-7b20-5bbf-acb5-52f396889bda
STIX ID: report--cfd76493-7b20-5bbf-acb5-52f396889bda
Feed Name: cybersecurityNews.com
This report analyzes DesckVB RAT, a 2026-era fileless Remote Access Trojan that uses heavily obfuscated JavaScript and PowerShell to load .NET assemblies directly into memory via reflection and process injection. It documents capabilities including keylogging, webcam access, AV-evasion and encrypted C2 communications, and provides IOCs (manikandan83.mysynology.net, 45.156.87.226:7535) and behavioral indicators (use of InstallUtil.exe, scripts dropped to C:\Users\Public), with recommended detection and mitigation steps such as blocking script execution, enabling detailed PowerShell logging, and keeping endpoint protection up to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
