LOBSHOT is a Windows remote-access malware family commonly characterized as a RAT with hidden VNC functionality. It has been observed in cybercriminal operations as a covert remote viewer that enables operators to interact with compromised systems through an invisible or user-hidden desktop session, allowing browser-based activity and other hands-on-keyboard actions without obvious on-screen artifacts. Reporting has associated it with Russian cybercriminal activity and with broader malware ecosystems that also distribute stealers and loaders.
LOBSHOT has appeared as a secondary payload in multi-stage intrusion chains. In one observed campaign cluster centered on CastleLoader, a shellcode-based loader delivered NetSupport RAT alongside a VNC-based remote viewer assessed to be a Lobshot variant. This places LOBSHOT in post-compromise workflows where an initial stager and loader establish execution before remote-access tooling is deployed for interactive control. The family has also been referenced in infrastructure tracking as RAT/hVNC malware.
The malware’s operational role is consistent with stealthy post-exploitation access, including hidden remote control of the victim host and likely support for follow-on credential or session abuse through attacker-operated browser sessions. LOBSHOT has also been cited in anti-analysis research as one of several malware families that checked for Windows Defender emulator artifacts, indicating some variants incorporate defense-evasion logic to avoid automated analysis environments.
Available information in this context supports LOBSHOT as a Windows-focused hVNC-style remote-access threat used in criminal campaigns, but does not establish a broader set of delivery mechanisms or a complete capability profile beyond covert remote access and evasion-related behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A VNC-based remote viewer observed as a downstream payload in the Urutyka campaign, likely used for remote access.
Related : New ‘Lobshot’ hVNC Malware Used by Russian Cybercriminals
RAT/hVNC malware family observed using infrastructure in the same subnet.
With the release of v0.16, here are the different malware families that we cover. blister deprecated ghostpulse latrodectus lobshot lumma netwire redlinestealer remcos smokeloader stealc strelastealer xorddos
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.