The Stealthy Evolution of the DesckVB RAT Infection Chain
ID: 59dfcbdb-c08c-5ee2-a3ca-7b62331aa5b2
STIX ID: report--59dfcbdb-c08c-5ee2-a3ca-7b62331aa5b2
Feed Name: securityonline.info
Lat61 Threat Intelligence reports on DesckVB RAT, a sophisticated JavaScript-based remote access Trojan active in 2026 that uses heavily obfuscated scripts to drop PowerShell and an in-memory .NET loader, employs process injection and legitimate utilities to evade detection, communicates with C2 over TLS on port 443, and includes modules for keylogging, webcam surveillance, AV detection and data exfiltration; defenders are advised to prioritize memory forensics and behavioral analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
