Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CoreRAT Malware Empowers Hackers with Full System Control

CoreRAT Malware Empowers Hackers with Full System Control

Posted on August 26, 2026 By CWS

The emergence of CoreRAT, a new remote access trojan, has provided the Core Werewolf hacking group with the ability to fully control compromised Windows systems. This malware was detected in operation between June and July 2026, with indications of activity dating back to March, marking a significant expansion in the group’s capabilities.

Phishing Tactics and Target Sectors

Using Telegram as a platform, the attackers distributed phishing messages that seemed legitimate, with files masquerading as official documents from military or government entities. Upon opening these files, victims were presented with a decoy PDF while the hidden malware was installed. The primary targets of these operations were within Russia’s public sector and defense industries.

BI.ZONE analysts have identified CoreRAT as a novel tool within the group’s arsenal, replacing previous use of legitimate remote access software like UltraVNC. The shift to custom malware such as CoreRAT enables hackers to modify it rapidly, evading detection and tailoring it to specific attacks.

Technical Analysis of CoreRAT

Developed in C++, CoreRAT encrypts its command-and-control addresses and internal text, which complicates analysis. Before executing, it checks for virtual environments, shutting down if detected to prevent analysis. On genuine systems, it gathers extensive data, including computer names, BIOS data, and network information, sending this encrypted data to its command server.

This malware’s capabilities extend to listing directories, inspecting processes, and collecting network configurations, allowing attackers to decide on subsequent actions, such as data theft or further compromise.

Delivery Methods and Deception

CoreRAT employs two delivery methods: a self-extracting 7z archive and a Rust-based dropper. Both techniques involve a decoy document to disguise the malicious activity. Such methods are reminiscent of the MostereRAT campaign, where benign-looking documents concealed remote access threats.

Decoy documents often contained unusual language and forged signatures, crafted to lower suspicion among recipients. Some files resembled those used by other hacking groups, yet lacked sufficient evidence of collaboration.

Preventive Measures and Recommendations

Organizations are advised to treat unexpected documents, especially those mimicking official notices, as potential threats. Security measures should include blocking suspicious network activities, monitoring endpoints for known file indicators, and scrutinizing outbound HTTPS traffic. Education and awareness are also crucial, as demonstrated by previous campaigns using trusted communication channels to disseminate malware.

Rapid detection and response are vital in minimizing damage. Affected devices should be isolated, credentials reset, and nearby hosts examined for similar indicators. Retaining evidence for further analysis is also crucial. Lessons from past campaigns underline the importance of scrutinizing all purported official documents.

Cyber Security News Tags:command-and-control, CoreRAT, cyber attacks, cyber threats, Cybersecurity, data security, defense industry, Hacking, Malware, network security, Phishing, remote access trojan, system compromise, threat intelligence, Windows systems

Post navigation

Previous Post: OpenSSL Vulnerabilities Pose Risks to Servers
Next Post: Gitea Vulnerability Exploited in Cryptojacking Attack

Related Posts

New Botnet Hijacks 9,000 ASUS Routers & Enables SSH Access by Injecting Public Key New Botnet Hijacks 9,000 ASUS Routers & Enables SSH Access by Injecting Public Key Cyber Security News
Dark Web Omertà Market Shut Downed Following the Leak of Real Server IPs Dark Web Omertà Market Shut Downed Following the Leak of Real Server IPs Cyber Security News
Gremlin Malware Hides C2 URLs in Encrypted Sections Gremlin Malware Hides C2 URLs in Encrypted Sections Cyber Security News
Fortinet Addresses Critical Vulnerabilities in Key Products Fortinet Addresses Critical Vulnerabilities in Key Products Cyber Security News
North Korean Hackers Make History with  Billion Crypto Heist in 2025 North Korean Hackers Make History with $2 Billion Crypto Heist in 2025 Cyber Security News
Fortinet Confirms Critical FortiCloud SSO Vulnerability(CVE-2026-24858) Actively Exploited in the Wild Fortinet Confirms Critical FortiCloud SSO Vulnerability(CVE-2026-24858) Actively Exploited in the Wild Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Nutex Health Data Breach Exposes Sensitive Details
  • AI-Based Phishing Scheme Targets Apple Device Owners
  • Microsoft Teams Restores Services After Outage
  • Gitea Vulnerability Exploited in Cryptojacking Attack
  • CoreRAT Malware Empowers Hackers with Full System Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Nutex Health Data Breach Exposes Sensitive Details
  • AI-Based Phishing Scheme Targets Apple Device Owners
  • Microsoft Teams Restores Services After Outage
  • Gitea Vulnerability Exploited in Cryptojacking Attack
  • CoreRAT Malware Empowers Hackers with Full System Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark