logo

A Closer Look at the Novel and Stealthy KarstoRAT Malware

ID: 3116255c-04cb-5c1d-9f0a-15cdd5e8a109

STIX ID: report--3116255c-04cb-5c1d-9f0a-15cdd5e8a109

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
70/100

Date Published: 2026-04-21

Date Updated: 2026-04-28

Author: Chen Aviani

...
...

KarstoRAT is a newly observed remote access trojan (early 2026) that performs system reconnaissance, keylogging, token theft, screenshot/audio/webcam exfiltration, remote code execution, and persistence; operators lure victims via a fake Roblox (Blox Fruits) marketplace and use an HTTP C2 with the user agent "SecurityNotifier" for commands and data exfiltration, and the malware includes disruptive features (text-to-speech, desktop inversion, mouse swap) and a remote self-destruct capability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.