Threats Tagged 'maas'
View all threats tagged with 'maas'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'maas'
Click on any threat for detailed analysis and mitigation recommendations
A Python-based Malware-as-a-Service builder enables operators to generate customized Windows infostealer executables. The system comprises a builder component and an embedded payload, using Nuitka or PyInstaller compilation to evade detection. The builder features automatic dependency installation, webhook configuration with XOR and Base64 encoding, and multiple compilation backends. The payload targets Chromium and Firefox browsers, extracting credentials, cookies, and credit card data. It harvests Wi-Fi passwords, Discord tokens, and Roblox session cookies while employing anti-analysis techniques including debugger detection, VM process blacklisting, disk size checks, and timing evasion. Persistence is established through registry Run keys and scheduled tasks. All stolen data is packaged into in-memory ZIP archives and exfiltrated via attacker-controlled webhooks, following a scalable affiliate model. Join the discussion | AlienVault OTX General | 09/28/2026, 10:51:14 UTC Added: 09/28/2026, 13:47:52 UTC |
RemControl is an Android banking trojan first observed in July 2026 that targets financial institutions across Western Europe, the Middle East, and Canada. The malware is distributed through fake Google Play Store pages advertising TVTap, an IPTV application, using malvertising campaigns with geo-targeted delivery. Once installed, the dropper creates a local VPN to block Play Protect checks and generates unique signing certificates per installation. RemControl exploits Android Accessibility Service permissions to display phishing overlays for over 30 banking applications, capturing PINs, mobile banking codes, and card details. The malware includes remote control capabilities, screen streaming, keylogging, and lock-screen pattern capture. It operates as Malware-as-a-Service with infrastructure showing evidence of AI-assisted development in phishing page creation and documentation. Join the discussion | AlienVault OTX General | 09/24/2026, 12:41:17 UTC Added: 09/24/2026, 19:33:01 UTC |
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands. MediumMalware Join the discussion | AlienVault OTX General | 09/08/2026, 12:29:01 UTC Added: 09/09/2026, 09:22:16 UTC |
ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications. Join the discussion | AlienVault OTX General | 09/02/2026, 13:39:04 UTC Added: 09/02/2026, 16:22:27 UTC |
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking. Join the discussion | AlienVault OTX General | 08/19/2026, 11:25:09 UTC Added: 08/19/2026, 15:52:33 UTC |
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t... Join the discussion | AlienVault OTX General | 08/18/2026, 15:06:19 UTC Added: 08/18/2026, 19:49:41 UTC |
Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem. Join the discussion | AlienVault OTX General | 07/23/2026, 16:30:34 UTC Added: 07/23/2026, 23:37:06 UTC |
TELEPUZ is a newly emerged modular malware-as-a-service first detected in April 2026, spreading through CLICKFIX-VIDAR infection chains. The lightweight, full-featured threat employs sophisticated evasion techniques including indirect syscalls, NTDLL unhooking, and anti-VM checks. It establishes persistence through service installation, communicates via WebSockets with C2 servers, and downloads additional modules for keylogging, credential theft, and web injection. The infection begins with social engineering tricks prompting victims to execute PowerShell commands, deploying VIDAR as a second stage which then delivers TELEPUZ components. Despite limited C2 infrastructure, high daily build volumes indicate active development and expanding operations by likely a small team or solo developer offering malware-as-a-service. Join the discussion | AlienVault OTX General | 07/16/2026, 02:29:55 UTC Added: 07/16/2026, 10:32:46 UTC |
SilabRAT is an advanced Remote Access Trojan offered as Malware-as-a-Service on Darkweb forums since late 2025, developed by threat actor o1oo1 and sold for $5,000 monthly. This financially-motivated tool focuses on credential theft and cryptocurrency operations, featuring Hidden Virtual Network Computing for invisible remote control, browser profile cloning to bypass session protections, and automated cryptocurrency wallet password cracking. The RAT bypasses Chrome App-Bound Encryption, performs session hijacking, and includes keylogging, clipboard monitoring, and remote desktop capabilities. Distributed through phishing and ClickFix campaigns with operator-hosted infrastructure, SilabRAT uses ChaCha20-Poly1305 encryption for command-and-control communications. The developer also offers AsmCrypt, a companion crypter service, creating a complete malware bundle from evasion to execution and remote control. Join the discussion | AlienVault OTX General | 06/10/2026, 11:58:30 UTC Added: 06/10/2026, 13:50:24 UTC |
A sophisticated fraud campaign exploiting Indonesia's tax season targeted 67 million residents through fake Coretax applications distributed via phishing websites and WhatsApp social engineering. The GoldFactory threat cluster orchestrated operations using Gigabud.RAT and MMRat malware families with shared infrastructure abusing over 16 trusted brands across government and financial sectors. The attack chain combines vishing, screen recording, and remote access capabilities to achieve device compromise and unauthorized financial transfers. Estimated financial impact reaches USD 1.5-2 million nationwide, with global implications extending to USD 6 million annually across multiple countries. The industrialized malware-as-a-service infrastructure enables horizontal scaling across Thailand, Vietnam, Philippines, and South Africa, demonstrating a shift toward unified cross-border operations that systematically undermine trust in digital government services. Join the discussion | AlienVault OTX General | 05/20/2026, 12:33:54 UTC Added: 05/21/2026, 16:29:45 UTC |
Showing 1 to 10 of 28 results