Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A new remote access trojan called Abyssos lets attackers control infected Windows systems.

The malware can steal credentials, collect files, and open remote viewing sessions, while its modular design allows operators to add functions after an infection.

Abyssos appeared in late June 2026 and remains in development. Its operators can issue commands through an encrypted connection, gather details about the victim computer, and retrieve modules.

The research does not identify a confirmed initial delivery method, leaving the campaign’s entry point unclear. No specific lure or exploit was identified.

Zscaler said in a report shared with Cyber Security News (CSN) that they found several versions and changing protections, suggesting the developers are actively refining it to make analysis and detection more difficult.

The immediate risk is broad access rather than one action. An intruder with control of an affected machine could search files, collect browser data, record the screen, run commands, or move toward more valuable accounts and systems.

That combination echoes concerns raised by recent RAT remote control, where a single foothold can support surveillance and theft.

One addition is a module named RDPWRAP, which Zscaler said may be related to the open-source rdpwrap library.

Remote Desktop Protocol lets users operate Windows machines remotely. A tool connected to that function can extend attacker access after compromise.

When instructed by its command server, Abyssos writes the module into the Windows temporary folder under a randomly generated name beginning with “rdp.”

It then runs exports called abyss and GetRdpWrapText, returning any output to the operator. The module is encrypted with AES-CBC before delivery, adding another obstacle for defenders examining network traffic or files.

The report does not say that the module automatically grants unrestricted Remote Desktop access on every victim. Still, its presence points to an effort to broaden what the malware can do on a compromised device.

The development is especially relevant as hidden remote desktop attacks show how remote-control features can be combined with credential theft to keep intrusions quiet.

Abyssos already supports hidden VNC sessions, screen recording, remote shells, file transfers, and process management.

The RDPWRAP-related capability sits alongside those functions, giving operators another possible route for interacting with a victim system. This mix can turn a basic infection into a long-running access point that is harder to investigate.

Modular Design Supports Theft

Abyssos uses a custom TCP protocol and AES-GCM encryption for most communications with its command-and-control server.

After starting, it collects host details such as the computer name, user name, privileges, Windows version, public IP address, and location, then sends that information to register the device.

Its commands can copy, delete, archive, upload, and download files. It can also capture clipboard contents and keystrokes, retrieve screenshots, stop or restart processes, and execute downloaded programs.

One feature can open Chrome with remote debugging enabled and load stolen cookies, a method that may let criminals take over an already authenticated browser session.

The malware can download modules for keylogging, Chrome and Firefox credential recovery, cookie collection, domain-controller discovery, vulnerability scanning, and attempts to raise privileges.

Such expandable toolsets resemble the danger in fileless loader evasion tactics, because security teams may face a changing set of capabilities instead of one fixed malicious file.

Abyssos also tries to frustrate analysts. Some samples check for virtual machines and common analysis processes, then stop if they find them.

The code uses control-flow changes, encrypted values, and hidden strings, although the newest version reviewed did not include all of these checks.

The malware is a post-compromise framework with file-system access and expandable modules.

Organizations investigating suspicious Windows activity should look for unexpected remote-control behavior, temporary-folder modules, and unusual encrypted outbound connections, while treating possible cookie theft as an account-security incident.

The wider lesson from browser cookie theft risks is that changing a password alone may not end an attacker’s active session.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 52b400c5be1557a8df146f62fde76d906e7e0a92ed76788717ef61c758f315aa Abyssos sample version 2.4F
IP address 213[.]145.86.42 Abyssos command-and-control server
SHA-256 ca94d95413210a2a325155740eb8a5c58627ad5c4e704478621e7fc8165fe173 Abyssos sample version 2.1F
IP address 209[.]99.184.223 Abyssos command-and-control server
File name windows_update_cache.json Hardcoded temporary-folder file used to store captured keystrokes
Mutex Global\68AA60E5-6C45-4C01-9F0E-E25FC57C652F Example Abyssos mutex format observed in the analysis

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world