CYFIRMA Research: DuplexSpy RAT- A Stealthy Windows Malware Enabling Full Remote Control and Surveillance
Manage episode 488106992 series 3472819
A highly modular Windows Remote Access Trojan (RAT), DuplexSpy, written in C#, has surfaced with advanced surveillance and system control capabilities.
Features include keylogging, remote shell access, screen & webcam spying, audio eavesdropping, and live C2 chat.
- It uses fileless execution, UAC bypass, registry persistence, and DLL injection to evade detection.
- Logs keystrokes in real time, records system audio, and hijacks webcams for covert monitoring.
- Comes with a GUI builder, making it accessible to low-skilled attackers.
- Communication is secured via RSA and AES encryption, complicating detection and analysis.
- First seen on April 15th, with ongoing updates expected, including browser data stealing and AD enumeration.
Link to the Research Report: https://www.cyfirma.com/research/duplexspy-rat-stealthy-windows-malware-enabling-full-remote-control-and-surveillance/
#DuplexSpy #CyberThreat #Malware #RemoteAccessTrojan #ThreatIntel
#InfoSec #CyberSecurity #RAT #CYFIRMA #CYFIRMAResearch
#ExternalThreatLandscapeManagement #ETLM
https://www.cyfirma.com/
222 episodes