Threats Tagged 'remote control'
View all threats tagged with 'remote control'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'remote control'
Click on any threat for detailed analysis and mitigation recommendations
A cluster of 31 Russian-language Chrome extensions masquerading as VPN services for blocked platforms like RuTracker, YouTube, Telegram, Instagram, ChatGPT, and Netflix shares a single malicious codebase. Published from three linked Google accounts, these extensions collectively affect approximately 356,000 users, with the flagship RuTracker VPN extension holding 200,000 installations. The extensions request extensive proxy permissions and dynamically fetch proxy server configurations from remote sources including GitHub Pages, Blogspot, Google Docs, and Telegram channels after installation. This architecture allows operators to modify traffic routing without pushing updates. The configuration uses obfuscated server lists with shared credentials and offers a paid VIP tier for 299 roubles. Some proxy hostnames match those used by Browsec VPN premium servers, suggesting a potential operational connection. Join the discussion | AlienVault OTX General | 09/29/2026, 06:34:53 UTC Added: 09/29/2026, 19:21:24 UTC |
Perseus is a new Android threat that builds upon earlier malware families like Cerberus and Phoenix. It enables real-time monitoring and interaction with infected devices through Accessibility-based remote sessions, allowing full Device Takeover. The malware focuses on extracting high-value personal information, including monitoring user notes. It employs strong anti-analysis measures to evade detection. Perseus is primarily distributed through IPTV applications, targeting users in Turkey and Italy. Its capabilities include overlay attacks, keylogging, and systematic exploration of note-taking apps. The malware performs extensive environment checks to detect analysis conditions and assess device risk. Perseus represents the ongoing evolution of mobile malware, adapting to remain effective in an increasingly secure mobile environment. Join the discussion | AlienVault OTX General | 03/19/2026, 11:00:48 UTC Added: 03/19/2026, 13:53:28 UTC |
A new Android banking Trojan named Massiv has been discovered, posing a significant threat to mobile banking users. This malware allows remote control of infected devices and enables Device Takeover attacks, leading to fraudulent transactions from victims' accounts. Massiv is distributed through side-loading, often masquerading as IPTV applications. It features overlay functionality, keylogging, and SMS/Push message interception to steal sensitive data. The malware has targeted government applications and digital identity wallets, particularly in Portugal. Massiv supports screen streaming and UI-tree modes for remote control, bypassing screen capture protections. The trend of malware masquerading as IPTV apps is increasing, exploiting users' willingness to install from unofficial sources. Join the discussion | AlienVault OTX General | 02/19/2026, 11:04:35 UTC Added: 02/19/2026, 12:50:31 UTC |
Sturnus is a newly identified Android banking trojan targeting financial institutions in Southern and Central Europe. It features advanced capabilities such as full device takeover, harvesting banking credentials, keylogging, and remote control via VNC. Notably, it can bypass encryption on popular messaging apps like WhatsApp, Telegram, and Signal to monitor communications. The malware uses sophisticated communication protocols including WebSocket and HTTP to interact with its command-and-control servers. Although still in development and not yet exploited in the wild, Sturnus poses a significant threat to financial security and user privacy. It employs HTML overlays for data exfiltration and extensive environment monitoring to evade detection. The malware’s complexity and targeting of Android devices make it a serious concern for European financial sectors. Defenders should prioritize detection and containment measures to mitigate potential impacts. Join the discussion | AlienVault OTX General | 11/20/2025, 19:42:43 UTC Added: 11/20/2025, 21:58:50 UTC |
Herodotus is a newly discovered Android malware designed to perform device takeover by mimicking human behavior to evade biometric and automated detection. It is distributed via side-loading and targets financial organizations and cryptocurrency wallets, with active campaigns observed in Italy and Brazil and potential for global spread. The malware is offered as Malware-as-a-Service and is linked to the Brokewell malware family. It steals credentials and remotely controls infected devices, using randomized delays between inputs to simulate human interaction. This behavior mimicry complicates detection by security solutions relying on behavioral analysis. The malware’s focus on financial targets and crypto wallets poses significant risks to confidentiality and financial integrity. European organizations, especially in Italy and Poland, are currently targeted and should prepare for potential expansion. Mitigation requires advanced layered security, including strict app installation policies, behavioral anomaly detection tuned for such mimicry, and user education on side-loading risks. Join the discussion | AlienVault OTX General | 10/28/2025, 18:24:45 UTC Added: 10/28/2025, 19:25:46 UTC |
A sophisticated SEO spam infection was discovered utilizing a cleverly crafted plugin that mimics the infected domain's name to avoid detection. The malware injects spam content into websites, targeting search engine rankings, and only activates under specific conditions like when a crawler is detected. The plugin's code is heavily obfuscated, using thousands of variable assignments broken into small parts. When decoded, the malware downloads files from external hosts, fetches remote content, and delivers custom spam to search engines while appearing normal to regular users. The attacker's domain, mag1cw0rld[.]com, is used for remote control. This technique allows the spam to remain undetected for longer periods, making it challenging to identify with traditional tools. Join the discussion | AlienVault OTX General | 07/06/2025, 13:13:42 UTC Added: 07/07/2025, 09:54:20 UTC |
A series of attacks targeting poorly managed MS-SQL servers have been identified, involving the installation of Ammyy Admin, a remote control tool. The attackers exploit vulnerable servers, execute commands to gather system information, and use WGet to install additional malware. The installed malware includes Ammyy Admin (mscorsvw.exe), its settings file (settings3.bin), and PetitPotato (p.ax). The attackers utilize an old version of Ammyy Admin (v3.10) and employ known exploitation methods to gain remote control. They also use PetitPotato for privilege escalation, adding new users and activating RDP services. To prevent such attacks, administrators are advised to use strong passwords, update software regularly, and implement security measures like firewalls. Join the discussion | AlienVault OTX General | 04/22/2025, 16:40:57 UTC Added: 05/22/2025, 16:07:19 UTC |
Showing 1 to 7 of 7 results