DesckVB RAT is a .NET-based remote access trojan active in 2026, including version 2.9, observed in malspam-driven campaigns and described as modular and plugin-based. Reported infection chains begin with a phishing email carrying an HTML attachment that redirects victims through Google DoubleClick tracking infrastructure to a personalized landing page; clicking a fake download button delivers a ZIP archive containing a JavaScript or Windows Script Host loader. In other observed chains, the malware starts from a heavily obfuscated JavaScript trojan that drops or launches a PowerShell payload. The PowerShell stage performs anti-analysis checks such as internet connectivity validation and debugger or sandbox detection, and then retrieves or loads a .NET loader directly into memory. Execution techniques described include fileless in-memory assembly loading, .NET reflection, use of InstallUtil.exe, and process hollowing into legitimate Microsoft-signed processes. The malware also establishes persistence, including via Run and RunOnce registry entries and a Startup-folder loader, and weakens defenses by patching or disabling AMSI and ETW and configuring Microsoft Defender exclusions.
DesckVB RAT provides comprehensive remote control of infected Windows hosts and supports data theft, command execution, reconnaissance, and delivery of additional payloads. Reported modules and capabilities include keylogging, antivirus or security product enumeration, webcam access or streaming via DirectShow, network communication, and remote control functions. The malware has been observed communicating with command-and-control infrastructure over encrypted HTTPS and also over raw TCP sockets, using custom-delimited plugin delivery in some reporting. High-confidence infrastructure and artifacts mentioned in the content include https://pastee.dev/d/ylacxzwj/0, andrefelipedonascime1768785037020.1552093.meusitehostgator.com.br, manikandan83.mysynology.net:7535, IP 45.156.87.226, and encrypted outbound traffic to 23.186.113.60:443. Reported payload and module names include ClassLibrary3.dll, ClassLibrary1.dll, Microsoft.exe, Keylogger.dll, okfIt.ps1, and a dropped PowerShell file at C:\Users\Public\lkpzw_01.ps1. The content also notes use of Base64 encoding, string reversal, heavy obfuscation, and replication of code into PowerShell and text files to conceal infrastructure and evade detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
It possesses capabilities for data extraction, command execution, and deploying further payloads...
DesckVB RAT is a highly active threat in 2026, operating as a JavaScript-based Trojan that initiates infection by deploying a PowerShell payload... The command powershell -ExecutionPolicy Bypass -File “C:\Users\Public\lkpzw_01.ps1” is executed.
DesckVB RAT is a highly active threat in 2026, operating as a JavaScript-based Trojan... The JavaScript file is heavily obfuscated and replicates its own code into both PowerShell and text files.
Using CreateProcessA, it spawns a new process in a suspended or controlled state... Additional logic suggests it may inject or manipulate the payload within the created process.
The Base64-encoded string was decoded to 0/jWzXCALY/d/ved.eetsap//:sptth , which reveals a reversed URL... the malware uses Base64 encoding combined with string reversal to conceal its command-and-control (C2) or payload hosting domain.
This sophisticated attack chain aims to bypass traditional detection methods by routing traffic through a legitimate Google-owned domain... leading the victim to a personalized landing page. This page dynamically incorporates company branding and location details, making it appear more convincing.
Using CreateProcessA, it spawns a new process in a suspended or controlled state... Additional logic suggests it may inject or manipulate the payload within the created process.
Inside, a JavaScript loader retrieves and executes a .NET RAT using a technique called process hollowing, injecting the malware into legitimate Microsoft processes.
The script attempts to connect to the domain ... and subsequently leverages the .NET Framework utility InstallUtil.exe to execute a malicious payload, a technique commonly used to bypass traditional security controls.
...while also attempting to detect and evade sandboxed environments or analysis tools.
Once launched, the trojan communicates with a command-and-control (C2) server over raw TCP sockets, carries out system reconnaissance
It possesses capabilities for data extraction, command execution, and deploying further payloads...
Once executed, the RAT establishes communication with a command-and-control (C2) server... the malware establishes a secure channel to receive instructions or exfiltrate data.
Notably, readable strings like “pastec.dev” and “http/1.1” suggest that the malware is attempting to communicate with an external server, likely for payload retrieval or command-and-control purposes.
The file triggers a meta-refresh browser redirect to a Google DoubleClick Campaign Manager click-tracking URL, from where the user is steered to another redirector, which decodes the Base64-encoded email address and leads the victim to a landing page
The malicious domain andrefelipedonascime1768785037020.1552093.meusitehostgator.com.br was observed delivering ClassLibrary3.dll via runtime in-memory loading.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET remote access trojan delivered via malspam that uses process hollowing to inject into legitimate Microsoft processes, establishes persistence, disables AMSI and ETW, communicates with a command-and-control server, supports data extraction and command execution, can deploy additional payloads, and includes sandbox/analysis evasion checks.
A .NET-based remote access trojan delivered via malspam. It uses a multi-stage infection chain involving JavaScript, PowerShell, and a .NET loader to evade analysis, disable security controls, establish persistence, inject into Microsoft-signed processes via process hollowing, communicate with C2 over raw TCP sockets, perform system reconnaissance, configure Microsoft Defender exclusions, patch AMSI and ETW, extract data, run commands, and deploy additional payloads.
A JavaScript-initiated remote access trojan that drops PowerShell, loads .NET assemblies in memory, communicates with C2 infrastructure, and supports remote control, data exfiltration, keylogging, antivirus detection, webcam access, and stealthy in-memory execution.
Remote access trojan family enabling comprehensive remote control over infected hosts; reported as newly discovered by threat hunters.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.