Abyssos is a modular C++ remote access trojan targeting Windows systems. It provides operators with broad post-compromise control, including credential theft, file collection and exfiltration, hidden VNC-based remote access, remote shell access, screenshot and screen-recording functionality, clipboard capture, process management, and execution of additional payloads. The malware communicates with command-and-control infrastructure over a custom TCP protocol, with most observed traffic encrypted using AES-GCM, and it registers infected hosts by transmitting host metadata such as system architecture, user context, integrity level, and geolocation-related information.
Abyssos is designed as an extensible framework. In addition to its built-in command set, it can download and execute auxiliary modules that expand functionality for keylogging, browser credential recovery, cookie theft, domain-controller discovery, vulnerability scanning, data collection, and privilege-escalation attempts. Observed functionality also includes browser session abuse by launching Chrome with remote debugging enabled and injecting stolen cookies, enabling session hijacking in addition to credential theft. The malware supports multiple payload-delivery and execution paths, including downloaded executables, shellcode-style execution, and DLL-based components.
The malware incorporates multiple defense-evasion and anti-analysis measures. Observed samples use LLVM-style obfuscation techniques such as control-flow flattening, bogus control flow, encrypted constants, hidden strings, and dynamic API resolution via checksum matching. Some versions also perform virtual-machine and analysis-process checks and terminate when virtualization artifacts are detected. Abyssos uses mutex-based single-instance enforcement and has shown ongoing changes across versions, indicating active development and iterative refinement of evasion and persistence-related behavior.
Abyssos has been observed with capabilities relevant to enterprise intrusion activity, including reconnaissance of host and network state, monitoring of processes and network connections, modification of local name-resolution behavior, and UAC-bypass techniques using native Windows mechanisms. An observed auxiliary component associated with RDP-related functionality suggests operators may extend remote-access options beyond the core hidden VNC feature set. No confirmed initial infection vector has been established from the available information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Furthermore, Abyssos uses a set of different intermediate representation (IR) passes to obfuscate the binary code. | Overall, we have observed different obfuscation passes including: Control flow flattening Bogus control flow with common opaque predicates Constant integer encryption Stack-based string obfuscation
Dynamically loads any required Windows API functions and libraries. Abyssos iterates the export directory of each loaded library, calculates the CRC32 checksum of the exported function, and compares the result against the expected/passed CRC32 checksum value.
The malware uses LLVM-based code obfuscation, anti-analysis techniques, and a custom TCP protocol for C2 communication.
Checks for the following process names and exits if any are running: vmtoolsd.exe vmwaretray.exe vmwareuser.exe VBoxService.exe VBoxTray.exe VBoxControl.exe xenservice.exe prl_tools.exe qemu-ga.exe spice-vdagent.exe vdservice.exe | Checks for the presence of hypervisors. Specifically, Abyssos uses the CPUID instruction to detect the presence of hypervisors, including VMware, KVM, Xen, and VirtualBox. If it detects any of these, Abyssos terminates execution.
Abyssos is a newly identified C++-based modular Remote Access Trojan (RAT) that supports credential theft, file exfiltration, and VNC-based remote access.
It can also capture clipboard contents and keystrokes, retrieve screenshots, stop or restart processes, and execute downloaded programs.
One feature can open Chrome with remote debugging enabled and load stolen cookies, a method that may let criminals take over an already authenticated browser session.
The malware can download modules for keylogging, Chrome and Firefox credential recovery, cookie collection, domain-controller discovery, vulnerability scanning, and attempts to raise privileges.
chrome_cdp: Starts the Chrome browser and injects cookies... The purpose of this is to hijack browser sessions.
GRABCOOKIES Likely a module that recovers browser cookies... After executing the module, Abyssos searches and sends any files located at %TEMP%\fontconfigs\ to the C2 server. This command might be combined with the aforementioned network command HVNC_PROG .
The malware can download modules for keylogging, Chrome and Firefox credential recovery, cookie collection, domain-controller discovery, vulnerability scanning, and attempts to raise privileges.
Some samples check for virtual machines and common analysis processes, then stop if they find them.
After starting, it collects host details such as the computer name, user name, privileges, Windows version, public IP address, and location, then sends that information to register the device.
GRABBER_START Creates a thread that scans and collects specified directories/files based on parameters.
The malware can download modules for keylogging, Chrome and Firefox credential recovery, cookie collection, domain-controller discovery, vulnerability scanning, and attempts to raise privileges.
The malware uses LLVM-based code obfuscation, anti-analysis techniques, and a custom TCP protocol for C2 communication.
Checks for the following process names and exits if any are running: vmtoolsd.exe vmwaretray.exe vmwareuser.exe VBoxService.exe VBoxTray.exe VBoxControl.exe xenservice.exe prl_tools.exe qemu-ga.exe spice-vdagent.exe vdservice.exe | Checks for the presence of hypervisors. Specifically, Abyssos uses the CPUID instruction to detect the presence of hypervisors, including VMware, KVM, Xen, and VirtualBox. If it detects any of these, Abyssos terminates execution.
It can also capture clipboard contents and keystrokes, retrieve screenshots, stop or restart processes, and execute downloaded programs.
It can also capture clipboard contents and keystrokes, retrieve screenshots, stop or restart processes, and execute downloaded programs.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly identified modular C++ RAT that supports credential theft, file exfiltration, VNC-based remote access, modular capability download from C2, LLVM-based code obfuscation, anti-analysis techniques, and a custom TCP protocol for command-and-control communication.
Abyssos is a Windows remote access trojan and modular post-compromise framework that enables attackers to control infected systems, steal credentials and cookies, collect files, record screens, run remote shells, manage processes, capture clipboard and keystrokes, and load additional modules for functions such as credential recovery, domain-controller discovery, vulnerability scanning, and privilege-escalation attempts. It uses encrypted C2 communications and includes anti-analysis features.
A newly identified modular C++ RAT/post-exploitation framework that provides remote administration, credential theft, file exfiltration, VNC-based remote access, process and file management, clipboard interception, keylogging support via modules, shell access, payload download/execution, shellcode injection, UAC bypass, and expandable functionality through additional downloaded modules. It uses AES-GCM for C2 traffic, supports numerous operator commands, and employs obfuscation and some anti-analysis checks.
Abyssos is a Windows remote access trojan/backdoor with anti-analysis checks, encrypted C2 communications, host registration, HVNC capability, remote shell access, file management, process and network monitoring, clipboard interception, screen recording, keylogging support, UAC bypass, payload download/execution, shellcode injection, and modular credential/cookie recovery functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.