logo

A New 'It RAT': Stealthy 'Resolver' Malware Burrows In

ID: 178814ed-0769-5add-90de-a02afcfdc6d7

STIX ID: report--178814ed-0769-5add-90de-a02afcfdc6d7

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-04-14

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

Morphisec researchers uncovered a phishing campaign delivering a new, sophisticated remote access Trojan dubbed "Resolver RAT" via DLL sideloading of a vulnerable Haihaisoft PDF Reader binary; the malware uses in-memory execution, encrypted strings, randomized C2 timing, control-flow flattening, resource resolver hijacking, and multiple persistence techniques, and has been observed targeting international organizations in healthcare and pharmaceuticals across several countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.