Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

The Security Coverage Gap is a Math Problem

June 26, 2026

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»New Atroposia RAT Surfaces on Dark Web
News

New Atroposia RAT Surfaces on Dark Web

Team-CWDBy Team-CWDOctober 30, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A new remote access trojan (RAT) dubbed Atroposia has been discovered by security researchers at Varonis.

The RAT uses encrypted command channels, hidden remote access, credential and wallet theft and persistence. It forms part of a growing market of criminal toolkits.

It was first identified by the cybersecurity firm on October 15 and has been observed being promoted on underground forums as a modular RAT with a full complement of offensive capabilities.

The package includes hidden remote desktop takeover (branded HRDP Connect), credential and cryptocurrency wallet theft, DNS hijacking and local vulnerability scanning.

Atroposia was seen priced at roughly $200 per month, $500 every three months or $900 for six months.

Varonis noted that the RAT could be combined with tools such as SpamGPT and MatrixPDF and used as a plug-and-play criminal toolkit.

SpamGPT is an AI-driven spam-as-a-service platform that automates phishing campaign creation, SMTP/IMAP cracking and deliverability tooling, effectively packaging marketing-grade campaign features for criminals.

MatrixPDF is a malicious PDF builder that weaponizes ordinary PDF files by adding overlays, redirects and embedded actions that help attackers bypass email filters and deliver phishing or malware lures.

Each package advanced attack capabilities into easy-to-use interfaces that automate phishing, delivery and data theft, the company noted in a recent blog where full technical details about the RAT can be found.

The Atroposia RAT uses techniques like an encrypted command and control (C2) server to foil traffic inspection. The malware also automatically escalates privileges via UAC bypass to gain admin rights and install multiple persistence mechanisms to survive reboots. 

These techniques mean Atroposia can bypass antivirus software and maintain long-term access without tipping off users or IT staff.

Daniel Kelley, a senior security researcher that works with Varonis, told Infosecurity, “Defending against Atroposia starts with reducing initial access through strong phishing defenses, regular patching, user training and multifactor authentication (MFA) enforcement. The next step is detecting post-compromise activity by monitoring authentication patterns and data flows to spot when legitimate accounts are used for lateral movement or data theft.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticlePolarEdge Targets Cisco, ASUS, QNAP, Synology Routers in Expanding Botnet Campaign
Next Article Meta Rolls Out New Tools to Protect WhatsApp and Messenger Users from Scams
Team-CWD
  • Website

Related Posts

News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
News

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
News

CMC Releases Analysis and Guidance for Education Sector After Canvas D

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

2025’s most common passwords were as predictable as ever

January 21, 2026

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

Top IRS scams to look out for in 2026

February 10, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.