logo

New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture

ID: dd3fd891-3b37-5696-87db-893e83b4fecb

STIX ID: report--dd3fd891-3b37-5696-87db-893e83b4fecb

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**DesckVB RAT v2.9** is a modular .NET Remote Access Trojan observed in early 2026 that uses an obfuscated WSH JavaScript stager and a PowerShell anti-analysis stage to deliver a fileless .NET loader; its plugin ecosystem (keylogger, webcam streamer, antivirus enumerator) and reflective in-memory execution enable stealthy persistence and espionage, and defenders are advised to monitor unusual wscript.exe activity, PowerShell scripts building decimal byte arrays, and reflective code loading.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.