Researchers documented several multi-stage malware campaigns delivering remote-access trojans including NetSupport RAT, Agent Tesla, Remcos RAT, and CastleRAT/NightShadeC2 through obfuscated scripts, phishing lures, and malicious installers. One NetSupport intrusion used Microsoft SafeLinks redirection, intermediary URLs, obfuscated JavaScript, and hidden PowerShell to fetch ZIP payloads via BITS, then launched client32.exe from an %AppData%\aragdrts folder and established persistence through scheduled tasks, Startup entries, and Registry Run keys. Separate analyses of Agent Tesla and Remcos samples showed BAT, CMD, JavaScript, and PowerShell stages that decoded or decrypted .NET payloads, with Agent Tesla configured for credential theft, keylogging, screen capture, and SMTP-based exfiltration, while Remcos included functions to disable Microsoft Defender and persist by copying its launcher into the Windows Startup path.
A later intrusion report showed how these commodity malware chains are being used for immediate fraud operations rather than only initial access. In that case, a malicious CarrierRegistration.msi delivered Matanbuchus, then NetSupport RAT, Remcos RAT, and finally CastleRAT, which was used to harvest browser credentials and proxy the victim’s live browser session into financial-site login attempts from the compromised host. The activity indicates a shift from simple information theft toward hands-on-keyboard account takeover, where attackers exploit stolen sessions and local browser context directly to evade fraud controls tied to device, IP, and session reputation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The malicious extension identified as version 2.2 with ID flkebkiofojicogddingbdmcmkpbplcd was removed from the Chrome Web Store, though installed copies could remain on affected systems and synced profiles.
Microsoft warned about a malicious Chromium-based extension, "Search for perplexity ai," that impersonated Perplexity AI and redirected browser searches through attacker-controlled infrastructure, exposing search traffic and related metadata.
Between December 4 and December 11, 2025, the actor harvested browser credentials and used CastleRAT to proxy the victim's live browser session for attempted logins to financial-institution websites. The report characterized the activity as account takeover-focused monetization rather than ransomware deployment or broader lateral movement.
On December 4, 2025, a multi-stage intrusion started with a malicious MSI file named CarrierRegistration.msi delivering the Matanbuchus loader, followed by NetSupport RAT, Remcos RAT, and CastleRAT. The operation targeted a real-estate-themed deception environment.
A malware analysis documented a Remcos RAT infection chain using an obfuscated CMD script, PowerShell, AES decryption, and Gzip decompression to recover .NET executables. The report identified persistence via the Windows startup path and noted functions for disabling Microsoft Defender, along with related hashes and network indicators.
An analysis traced an Agent Tesla sample from a BAT file through obfuscated PowerShell and .NET payloads to a final information-stealing and keylogging implant that exfiltrated data via SMTP. The report also listed hashes, delivery infrastructure, and email addresses associated with the activity.
A report described a phishing campaign delivering NetSupport RAT through Microsoft SafeLinks abuse, intermediary redirects, obfuscated JavaScript, and PowerShell. The analysis published domains, URLs, IPs, hashes, filenames, and persistence details tied to the campaign.
A blog post analyzed an Agent Tesla Windows executable sample obtained from Malware Bazaar and documented capabilities including credential harvesting, keylogging, screen capture, host discovery, and likely email-based data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourceblog.deception.pro
Open sourcemedium.com
Open sourcemedium.com
Open sourcemedium.com
Open sourcedenwp.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.