A fresh remote access trojan, also called Silver RAT, has emerged as a serious cybersecurity threat, especially to Windows-based systems. Discovered late in 2024, the malware has been a cause of concern because it can bypass conventional antivirus software while performing all forms of malicious behavior. These include data theft, logging user input, to granting full remote access to infected computers to attackers. Since it is modular, Silver RAT makes it easy for attackers to install extra functionality, making it a significant threat to citizens, businesses, and critical infrastructure globally. What is so dangerous about Silver RAT is its sophisticated way of evading detection. It employs process hollowing to inject malicious payloads into legitimate system processes, dynamic API resolution to hide its behavior at runtime, and obfuscation to hide its code. These techniques enable the malware to evade static and signature-based detection tools. Its communication with command-and-control servers is also encrypted, making it even more difficult to trace. The malware has been shown to already target high-priority sectors like finance, health care, and government, spreading normally through phishing email, infected websites, or malicious software updates. The sophistication and resources that have clearly been put into Silver RAT make it likely to be the work of an advanced, and potentially state-sponsored, actor. To protect against this latest threat, professionals recommend an active approach to cybersecurity. Companies must bolster endpoint security systems, have up-to-date software, and offer recurrent employee training to identify phishing methods. Behavior-based threat detection software installation is also required, as conventional protection will not be able to identify sophisticated malware such as Silver RAT in advance.
CERT-UA has reported a large-scale phishing campaign in which threat actors impersonated the agency to distribute a remote access trojan (RAT) known as AGEWHEEZE. The campaign, att...
A critical vulnerability identified as CVE-2026-33026 affects the backup and restore functionality of nginx-ui, exposing systems to severe security risks. This flaw enables attacke...
Microsoft has identified a new malware campaign that distributes malicious Visual Basic Script (VBS) files through WhatsApp messages, targeting Windows users. The campaign relies h...