New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture
ID: dd3fd891-3b37-5696-87db-893e83b4fecb
STIX ID: report--dd3fd891-3b37-5696-87db-893e83b4fecb
Feed Name: cybersecurityNews.com
**DesckVB RAT v2.9** is a modular .NET Remote Access Trojan observed in early 2026 that uses an obfuscated WSH JavaScript stager and a PowerShell anti-analysis stage to deliver a fileless .NET loader; its plugin ecosystem (keylogger, webcam streamer, antivirus enumerator) and reflective in-memory execution enable stealthy persistence and espionage, and defenders are advised to monitor unusual wscript.exe activity, PowerShell scripts building decimal byte arrays, and reflective code loading.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
