Pulsar RAT Abuses Memory-Only Execution and HVNC for Stealthy Remote Takeover
ID: 517868a6-3165-5772-9b3d-83db8e79b0d6
STIX ID: report--517868a6-3165-5772-9b3d-83db8e79b0d6
Feed Name: GBHackers
Pulsar RAT is a sophisticated, modular remote-access trojan targeting Windows that leverages fileless memory-only payloads, anti-virtualization checks, code injection, hidden VNC (HVNC), and modules for credential and cryptocurrency wallet theft; it spreads via phishing, cracked software and supply-chain compromises (notably 2025 npm packages), retrieves encrypted C2 configurations from public services, and requires layered detection and remediation to mitigate significant operational and data-exfiltration risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
