Abyssos: Technical Analysis of a New Modular RAT

    Date: 08/11/2026

    Severity: High

    Summary

    Abyssos is a newly identified C++-based modular Remote Access Trojan (RAT) that supports credential theft, file exfiltration, and VNC-based remote access. The malware uses LLVM-based code obfuscation, anti-analysis techniques, and a custom TCP protocol for C2 communication. Its modular design allows attackers to download additional capabilities from the C2 server, while ongoing development and evolving obfuscation indicate a growing focus on evasion and persistence.

    Indicators of Compromise (IOC) List

    IP Address

    213.145.86.42

    209.99.184.223

    Hash

    52b400c5be1557a8df146f62fde76d906e7e0a92ed76788717ef61c758f315aa

    ca94d95413210a2a325155740eb8a5c58627ad5c4e704478621e7fc8165fe173

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("213.145.86.42","209.99.184.223") or srcipaddress IN ("213.145.86.42","209.99.184.223")

    Detection Query 2 :

    sha256hash IN ("ca94d95413210a2a325155740eb8a5c58627ad5c4e704478621e7fc8165fe173","52b400c5be1557a8df146f62fde76d906e7e0a92ed76788717ef61c758f315aa")

    Reference:    

    https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat#                                               


    Tags

    MalwareRATCredential HarvestingExfiltrationObfuscation

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags