Cyber Security News

Threat Actors Allegedly Selling SnowDog RAT Malware With Control Panel on Hacker Forums

A new Remote Access Trojan (RAT) dubbed “SnowDog RAT” is malicious software purportedly marketed for $300 per month. It appears to have been specifically developed for corporate espionage and targeted attacks on business environments. 

The malware advertisement, discovered on Thursday, April 3, 2025, describes sophisticated capabilities that could threaten organizations worldwide.

Malware Capabilities and Features

According to a ThreatMon post shared on X, the advertisement claims that SnowDog RAT offers an extensive array of intrusion and persistence features that make it particularly dangerous. 

The malware reportedly includes a web-based command and control (C2) interface that allows attackers to remotely manage infected systems. 

This includes functionality for creating both the RAT payload and various delivery methods, such as HTML-to-DOCM and ISO file conversion techniques.

The RAT allegedly enables attackers to download files and directories from compromised machines functionally with a single click. 

Additionally, it can execute files directly from memory within system processes, a “living off the land” technique that helps evade detection by traditional security solutions.

This type of malware represents a significant evolution in commercially available RATs. The ability to cryptographically protect each assembly at creation time with a proprietary algorithm makes it particularly challenging to detect using signature-based methods.

Technical Specifications and Delivery

Security analysis of the advertisement reveals the malware utilizes advanced techniques similar to those seen in state-sponsored attacks. 

SnowDog RAT reportedly creates unique fly assemblies for each target, implements transport connectors for communication, and leverages TOR networks for bot control to obfuscate command traffic.

The malware appears designed to establish persistence by starting from trusted process memory and opening web console connections with remote machines using administrator rights. 

This grants the attacker full PowerShell command execution capabilities, allowing for lateral movement within compromised networks.

Remote Access Trojans like SnowDog represent a hazardous category of malware. Once installed, RATs typically run silently in the background without appearing in active programs or task lists, maintaining an ongoing communication channel with command and control servers.

The advertisement mentions targeted attacks on corporations, indicating the tool is being marketed for potential corporate espionage or ransomware deployment.

Similar RATs have been used in sophisticated attacks to steal sensitive information, capture keystrokes, activate webcams, take screenshots, and even download additional malicious payloads.

Security experts recommend organizations implement robust email filtering, keep systems updated with security patches, utilize behavior-based endpoint protection, and maintain comprehensive network monitoring to detect unusual data transfers or communication patterns that might indicate RAT activity.

User awareness training remains critical, as RATs are typically delivered through social engineering tactics like phishing emails. 

Organizations should also implement application allowlisting and network segmentation to limit the potential damage if a system becomes compromised.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago