logo

STX RAT: The New Financial Predator Hiding in the “Start of Text”

ID: 86f69e86-7a56-5513-bd1b-f699f92a6791

STIX ID: report--86f69e86-7a56-5513-bd1b-f699f92a6791

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-13

Date Updated: 2026-04-23

Author: Ddos

...
...

eSentire’s TRU identified STX RAT, a sophisticated remote access trojan targeting the finance sector that uses VBScript and trojanized FileZilla installers for delivery, supports a hidden VNC (HVNC) remote desktop, gates credential/data theft behind active C2 interaction, employs strong evasion (string obfuscation, AMSI Ghosting, API hashing) and secures C2 with X25519/Ed25519 over TCP with Tor fallback, representing a high-risk stealthy threat to financial organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.