logo

Packed With Features, 'SambaSpy' RAT Delivers Hefty Punch

ID: c4b67d60-a716-5833-95bf-afc2a7719dce

STIX ID: report--c4b67d60-a716-5833-95bf-afc2a7719dce

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-09-18

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers uncovered SambaSpy, a Java-based remote access Trojan (RAT) obfuscated with Zelix KlassMaster and distributed via phishing campaigns that specifically target Italian users (with signs of expansion to Spain and Brazil). The RAT provides broad espionage and data-theft capabilities — remote file operations, plugin loading, screenshots, webcam control, keystroke logging, and credential theft — and uses environment checks and obfuscation to evade analysis, making it a versatile tool for targeted information stealing and other criminal activities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.