Packed With Features, 'SambaSpy' RAT Delivers Hefty Punch
ID: c4b67d60-a716-5833-95bf-afc2a7719dce
STIX ID: report--c4b67d60-a716-5833-95bf-afc2a7719dce
Feed Name: Dark Reading
Researchers uncovered SambaSpy, a Java-based remote access Trojan (RAT) obfuscated with Zelix KlassMaster and distributed via phishing campaigns that specifically target Italian users (with signs of expansion to Spain and Brazil). The RAT provides broad espionage and data-theft capabilities — remote file operations, plugin loading, screenshots, webcam control, keystroke logging, and credential theft — and uses environment checks and obfuscation to evade analysis, making it a versatile tool for targeted information stealing and other criminal activities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
