Cybercriminals are actively marketing a new remote access trojan (RAT) called Atroposia as a plug-and-play malware-as-a-service (MaaS) platform, enabling even low-skill threat actors to launch sophisticated attacks. Atroposia is available via underground forums for a subscription fee, offering a modular toolkit that includes hidden remote desktop access, credential and cryptocurrency wallet theft, DNS hijacking, clipboard monitoring, and a local vulnerability scanner. The malware communicates with its command-and-control (C2) infrastructure over encrypted channels, employs multiple persistence mechanisms, and can bypass User Account Control (UAC) on Windows systems to escalate privileges. Its user-friendly control panel and plugin builder further lower the technical barrier for cybercriminals, making advanced attack techniques widely accessible.
Researchers at Varonis and other security firms have highlighted Atroposia's role in the growing trend of turnkey criminal toolkits, which also includes platforms like SpamGPT and MatrixPDF. These toolkits bundle discovery, delivery, and evasion features into easy-to-use interfaces, allowing attackers to automate phishing campaigns, weaponize documents, and maintain stealthy, persistent access to compromised systems. Atroposia's affordability and comprehensive feature set make it a significant threat to enterprises, as it enables rapid deployment of complex attacks by a broader range of adversaries.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Varonis researchers publicly documented Atroposia as a modular RAT featuring encrypted command channels, persistence, credential and cryptocurrency theft, DNS hijacking, local vulnerability scanning, and covert hidden RDP access. The research warned that the malware's design lowers the barrier to entry for sophisticated attacks and could see broader adoption.
A new malware-as-a-service offering called Atroposia began being sold on underground forums as a turnkey remote access Trojan. It was advertised with subscription pricing starting at $200 per month and positioned as usable by low-skilled cybercriminals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecsoonline.com
Open sourcevaronis.com
Open sourcebleepingcomputer.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.