logo

The Stealthy Evolution of the DesckVB RAT Infection Chain

ID: 59dfcbdb-c08c-5ee2-a3ca-7b62331aa5b2

STIX ID: report--59dfcbdb-c08c-5ee2-a3ca-7b62331aa5b2

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-05-05

Author: Ddos

...
...

Lat61 Threat Intelligence reports on DesckVB RAT, a sophisticated JavaScript-based remote access Trojan active in 2026 that uses heavily obfuscated scripts to drop PowerShell and an in-memory .NET loader, employs process injection and legitimate utilities to evade detection, communicates with C2 over TLS on port 443, and includes modules for keylogging, webcam surveillance, AV detection and data exfiltration; defenders are advised to prioritize memory forensics and behavioral analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.