logo

Saefko: A new multi-layered RAT

ID: e04cfc60-6396-531b-9fb6-0aa2e9fb8513

STIX ID: report--e04cfc60-6396-531b-9fb6-0aa2e9fb8513

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzed Saefko, a .NET remote-access trojan sold on dark web marketplaces that persists via autostart registry keys, profiles victims by parsing browser history (credit-card, crypto, shopping, business, social/gaming categories), and can exfiltrate screenshots, webcam video, keylogs, and system/location info to HTTP/IRC command-and-control servers; it also supports USB propagation and remote payload execution. The report provides detailed technical behavior, command lists, required libraries, sample IOCs (MD5s, downloader and network URLs), and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.