STX RAT Hides Remote Desktop, Steals Data to Dodge Detection
ID: b3936d6f-14d1-5156-bbc4-aff7423d0fcc
STIX ID: report--b3936d6f-14d1-5156-bbc4-aff7423d0fcc
Feed Name: GBHackers
**STX RAT — stealthy remote access trojan**: STX RAT is a mature, low‑visibility RAT first observed in February 2026 that pairs a Hidden VNC–style remote desktop with staged infostealer capabilities; it uses malicious VBS/JScript chains and trojanized installers for initial access, performs in-memory execution via a PowerShell loader and custom packer, employs modern cryptography (X25519/Ed25519/ChaCha20‑Poly1305) for encrypted TCP C2, and implements extensive anti-analysis and persistence techniques, leading defenders to harden script execution, deploy NGAV/EDR, and consider 24×7 MDR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
