Multiple reports highlight continued growth in commercially sold malware—particularly infostealers and remote-access tooling—lowering the barrier for credential theft and enterprise targeting. Fortinet-described activity shows a phishing-led Agent Tesla delivery chain using business-themed lures (e.g., purchase orders), compressed attachments, and obfuscated scripting (e.g., .jse) to execute largely in-memory, leveraging techniques such as process hollowing and anti-analysis to reduce on-disk artifacts and evade endpoint controls while stealing browser, email, and other credentials.
Separately, researchers described new or increasingly marketed “as-a-service” tools that expand attacker capability across both Windows and Android. Flashpoint detailed DarkCloud, a low-cost infostealer sold via Telegram/clearnet that targets a wide range of browsers and enterprise-adjacent applications (email clients, FTP tools, VPNs), and uses legacy components (e.g., MSVBVM60.DLL) to complicate modern detection. Certo reported Oblivion, an Android RAT sold via subscription that targets Android 8–16 and emphasizes automated permission bypass and hidden remote control (HVNC/VNC-like) functionality alongside SMS/2FA interception and device takeover features. BlackFog reported Steaelite, a Windows RAT marketed to enable double extortion by combining data theft and ransomware deployment workflows in a single web panel, with HVNC monitoring and an announced Android ransomware module in development. A separate 2025 retrospective from TG Soft’s C.R.A.M. reinforces that malspam-delivered password stealers remain prevalent, with Agent Tesla, FormBook, and Remcos among the most common families observed in email campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Gen Digital disclosed Torg Grabber as a newly identified malware-as-a-service credential stealer that evolved over roughly three months from Telegram-based exfiltration to an encrypted HTTPS REST API command-and-control model. The report described broad credential and wallet theft capabilities, a multi-stage delivery chain using fake cheats, cracked software, and ClickFix lures, and evidence of use by multiple operators tied to Russian-speaking cybercrime networks.
Fortinet researchers reported a phishing campaign using business-themed lures and a RAR-delivered .jse loader to fetch and decrypt multiple in-memory stages that ultimately run Agent Tesla. The campaign used PowerShell, process hollowing into aspnet_compiler.exe, anti-analysis checks, and SMTP-based data exfiltration to evade detection.
Certo identified Oblivion as a subscription-based Android RAT targeting Android 8 through 16, with a builder for droppers and fake apps. The malware was reported to support SMS interception, banking-notification theft, keylogging, file management, hidden VNC control, and permission-bypass techniques across multiple Android OEM skins.
Flashpoint reported that DarkCloud remained a significant initial-access threat in 2026 because of its low cost and broad theft capabilities across browsers, email clients, file transfer tools, and VPN applications. The analysis highlighted its VB6-based implementation, layered string encryption, and multiple exfiltration channels including SMTP, FTP, Telegram, and HTTP.
BlackFog reported that Steaelite automatically exfiltrates victim data immediately after connection and provides operators with capabilities including remote code execution, hidden RDP, ransomware deployment, Defender disabling, persistence, UAC bypass, and a crypto clipper. The report also noted the developer had announced an Android ransomware module as in development and published indicators of compromise.
A threat actor publicly advertised the Oblivion Android RAT on a hacking forum, sharing product details and a video demonstration. The seller claimed the malware had been tested in live environments for more than four months without behavioral detections before release.
Steaelite, a browser-managed remote access trojan built to combine data theft and ransomware deployment for double-extortion operations, was first observed on underground cybercrime networks in November 2025. It was marketed as an easy-to-use all-in-one platform that lowered the barrier for less-skilled extortion actors.
Kaspersky researchers reported on CrystalX RAT, a remote access trojan distributed under a malware-as-a-service model. The malware was described as combining spyware, credential-stealing, and prankware capabilities, indicating use for surveillance, data theft, and disruptive actions by multiple operators.
DarkCloud, a commercially available credential-stealing malware family later sold via Telegram and a clearnet storefront, was first observed in 2022. Flashpoint also noted code-level similarities to A310LoggerStealer/BluStealer, suggesting an earlier lineage or iteration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.