Date: 08/11/2026
Severity: High
Summary
Abyssos is a newly identified C++-based modular Remote Access Trojan (RAT) that supports credential theft, file exfiltration, and VNC-based remote access. The malware uses LLVM-based code obfuscation, anti-analysis techniques, and a custom TCP protocol for C2 communication. Its modular design allows attackers to download additional capabilities from the C2 server, while ongoing development and evolving obfuscation indicate a growing focus on evasion and persistence.
Indicators of Compromise (IOC) List
IP Address | 213.145.86.42 209.99.184.223 |
Hash | 52b400c5be1557a8df146f62fde76d906e7e0a92ed76788717ef61c758f315aa
ca94d95413210a2a325155740eb8a5c58627ad5c4e704478621e7fc8165fe173
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | dstipaddress IN ("213.145.86.42","209.99.184.223") or srcipaddress IN ("213.145.86.42","209.99.184.223") |
Detection Query 2 : | sha256hash IN ("ca94d95413210a2a325155740eb8a5c58627ad5c4e704478621e7fc8165fe173","52b400c5be1557a8df146f62fde76d906e7e0a92ed76788717ef61c758f315aa")
|
Reference:
https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat#