Cyber Security News

New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture

A sophisticated new threat has surfaced in the wild, identified as the DesckVB RAT version 2.9. This modular Remote Access Trojan, built on the .NET framework, has been observed in active malware campaigns throughout early 2026.

Unlike simple backdoors, this threat demonstrates a high level of operational maturity, designed to establish persistent control over compromised systems while evading traditional defense mechanisms.

The malware initiates its attack through a highly obfuscated Windows Script Host (WSH) JavaScript file.

This initial stager performs critical setup tasks, such as copying itself to public user directories and executing via the wscript engine to mask its activity.

By leveraging native Windows components, the attackers can blend their malicious traffic with legitimate system processes, complicating detection efforts for security teams.

GitHub analysts noted that this initial activity is merely a gateway, setting the stage for a more potent payload.

Following the initial execution, the infection chain transitions into a PowerShell stage that performs rigorous anti-analysis checks.

It verifies internet connectivity and scans for debugging tools, ensuring the environment is safe before downloading the core malicious components. This careful validation prevents the malware from executing in sandboxes.

The impact of DesckVB RAT lies in its stability and stealth. By using a fileless .NET loader, the malware executes directly in memory without leaving a physical footprint on the disk.

This “living off the land” approach allows it to bypass many static file scanning defenses, making forensic analysis significantly more challenging for incident responders.

Modular Plugin Ecosystem

The most defining feature of DesckVB RAT is its robust plugin-based architecture, which allows operators to extend capabilities dynamically.

Instead of bundling every malicious function into a single executable, the attackers can selectively deploy specific modules post-compromise based on the target’s value.

Validated plugins include a comprehensive keylogger that tracks active windows, a webcam streamer using DirectShow, and an antivirus enumerator that reports installed security products.

These modules are delivered via a custom TCP protocol that uses distinct delimiters to manage payloads.

This flexibility transforms the RAT from a simple backdoor into a versatile espionage tool, capable of adapting to various operational needs without requiring a complete re-infection of the host system.

Security professionals are advised to focus on behavioral detection to mitigate this threat.

Monitoring for unusual wscript.exe execution and PowerShell scripts building decimal byte arrays can provide early warning signs.

Ensuring that endpoint detection systems are tuned to spot reflective code loading is also essential for effective mitigation against these evolving attacks.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago