Zscaler ThreatLabz disclosed Abyssos, a newly identified modular Windows remote access trojan written in C++ that combines surveillance, credential theft, file exfiltration, and post-exploitation features. The malware uses anti-analysis checks for hypervisors and running processes, dynamically resolves Windows APIs with CRC32 checksums, creates a mutex to ensure a single instance, and registers infected hosts to command-and-control infrastructure with a HELLO message carrying host metadata and the malware version. Researchers said Abyssos is under active development, with multiple observed versions including 2.4F and 2.1F and differing obfuscation across samples.
Abyssos communicates over a custom TCP protocol encrypted mainly with AES-GCM using a hardcoded 32-byte key, while some downloaded modules rely on AES-CBC or XOR-based decryption. Its command set enables hidden VNC remote desktop access, browser session hijacking, clipboard interception, process and network monitoring, remote shell access, payload execution, UAC bypass, self-deletion, and broad file operations. Auxiliary modules extend the malware with keylogging, cookie and credential theft, domain controller discovery, vulnerability scanning, SYSTEM token elevation, and possible RDP-related functionality, and the report included associated sample hashes and command-and-control IP addresses.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Zscaler ThreatLabz reported a newly identified malware family named Abyssos and described it as a modular C++ remote administration tool with credential theft, file exfiltration, VNC-based remote access, and post-exploitation capabilities.
ThreatLabz published a technical analysis of Abyssos version 2.4F, detailing its anti-analysis logic, dynamic API resolution, encrypted C2 communications, extensive command set, and auxiliary modules. The report also noted multiple versions in active development and listed sample hashes and C2 IP addresses tied to versions 2.4F and 2.1F.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.