Threats Tagged 'vnc'
View all threats tagged with 'vnc'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'vnc'
Click on any threat for detailed analysis and mitigation recommendations
ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications. Join the discussion | AlienVault OTX General | 09/02/2026, 13:39:04 UTC Added: 09/02/2026, 16:22:27 UTC |
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t... Join the discussion | AlienVault OTX General | 08/18/2026, 15:06:19 UTC Added: 08/18/2026, 19:49:41 UTC |
ESET researchers have discovered PromptSpy, the first known Android malware to abuse generative AI in its execution flow. This malware uses Google's Gemini AI to analyze screen content and provide instructions for UI manipulation, allowing it to adapt to various devices and layouts. PromptSpy's main purpose is to deploy a VNC module for remote access to the victim's device. It also abuses the Accessibility Service to block uninstallation, captures lockscreen data, and records video. The campaign appears to target users in Argentina and was likely developed in a Chinese-speaking environment. PromptSpy demonstrates how incorporating AI tools can make malware more dynamic and capable of real-time decision-making, potentially expanding the pool of potential victims. Join the discussion | AlienVault OTX General | 02/19/2026, 20:16:49 UTC Added: 02/20/2026, 13:13:40 UTC |
Albiriox is a newly discovered Android RAT malware offered as Malware-as-a-Service, primarily targeting financial and cryptocurrency applications globally. It uses a sophisticated two-stage deployment involving dropper apps and packing to evade detection. The malware enables remote control of infected devices via VNC-based access and overlay attacks, allowing real-time interaction and unauthorized operations such as screen manipulation and device takeover. It targets over 400 financial and crypto wallet apps, facilitating on-device fraud while remaining stealthy. The MaaS model and ongoing development indicate potential rapid spread among cybercriminals. Although no known exploits in the wild are reported yet, its advanced capabilities pose a significant threat to mobile users, especially in finance sectors. The malware is linked to Russian-speaking threat actors and uses multiple fake domains for distribution. European organizations with mobile banking and crypto wallet users are at risk, particularly in countries with high Android usage and financial sector prominence. Mitigation requires targeted detection of dropper apps, user education on app sources, and enhanced mobile endpoint protection. Given its impact on confidentiality, integrity, and availability with ease of exploitation and no user interaction needed post-installation, the threat severity is assessed as high. Join the discussion | AlienVault OTX General | 12/03/2025, 20:19:09 UTC Added: 12/04/2025, 11:23:20 UTC |
Sturnus is a newly identified Android banking trojan targeting financial institutions in Southern and Central Europe. It features advanced capabilities such as full device takeover, harvesting banking credentials, keylogging, and remote control via VNC. Notably, it can bypass encryption on popular messaging apps like WhatsApp, Telegram, and Signal to monitor communications. The malware uses sophisticated communication protocols including WebSocket and HTTP to interact with its command-and-control servers. Although still in development and not yet exploited in the wild, Sturnus poses a significant threat to financial security and user privacy. It employs HTML overlays for data exfiltration and extensive environment monitoring to evade detection. The malware’s complexity and targeting of Android devices make it a serious concern for European financial sectors. Defenders should prioritize detection and containment measures to mitigate potential impacts. Join the discussion | AlienVault OTX General | 11/20/2025, 19:42:43 UTC Added: 11/20/2025, 21:58:50 UTC |
Showing 1 to 5 of 5 results