Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CoreRAT Malware Empowers Hackers with Full System Control

CoreRAT Malware Empowers Hackers with Full System Control

Posted on August 26, 2026 By CWS

The emergence of CoreRAT, a new remote access trojan, has provided the Core Werewolf hacking group with the ability to fully control compromised Windows systems. This malware was detected in operation between June and July 2026, with indications of activity dating back to March, marking a significant expansion in the group’s capabilities.

Phishing Tactics and Target Sectors

Using Telegram as a platform, the attackers distributed phishing messages that seemed legitimate, with files masquerading as official documents from military or government entities. Upon opening these files, victims were presented with a decoy PDF while the hidden malware was installed. The primary targets of these operations were within Russia’s public sector and defense industries.

BI.ZONE analysts have identified CoreRAT as a novel tool within the group’s arsenal, replacing previous use of legitimate remote access software like UltraVNC. The shift to custom malware such as CoreRAT enables hackers to modify it rapidly, evading detection and tailoring it to specific attacks.

Technical Analysis of CoreRAT

Developed in C++, CoreRAT encrypts its command-and-control addresses and internal text, which complicates analysis. Before executing, it checks for virtual environments, shutting down if detected to prevent analysis. On genuine systems, it gathers extensive data, including computer names, BIOS data, and network information, sending this encrypted data to its command server.

This malware’s capabilities extend to listing directories, inspecting processes, and collecting network configurations, allowing attackers to decide on subsequent actions, such as data theft or further compromise.

Delivery Methods and Deception

CoreRAT employs two delivery methods: a self-extracting 7z archive and a Rust-based dropper. Both techniques involve a decoy document to disguise the malicious activity. Such methods are reminiscent of the MostereRAT campaign, where benign-looking documents concealed remote access threats.

Decoy documents often contained unusual language and forged signatures, crafted to lower suspicion among recipients. Some files resembled those used by other hacking groups, yet lacked sufficient evidence of collaboration.

Preventive Measures and Recommendations

Organizations are advised to treat unexpected documents, especially those mimicking official notices, as potential threats. Security measures should include blocking suspicious network activities, monitoring endpoints for known file indicators, and scrutinizing outbound HTTPS traffic. Education and awareness are also crucial, as demonstrated by previous campaigns using trusted communication channels to disseminate malware.

Rapid detection and response are vital in minimizing damage. Affected devices should be isolated, credentials reset, and nearby hosts examined for similar indicators. Retaining evidence for further analysis is also crucial. Lessons from past campaigns underline the importance of scrutinizing all purported official documents.

Cyber Security News Tags:command-and-control, CoreRAT, cyber attacks, cyber threats, Cybersecurity, data security, defense industry, Hacking, Malware, network security, Phishing, remote access trojan, system compromise, threat intelligence, Windows systems

Post navigation

Previous Post: OpenSSL Vulnerabilities Pose Risks to Servers
Next Post: Gitea Vulnerability Exploited in Cryptojacking Attack

Related Posts

ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details Cyber Security News
Darkhub: A Dark Web Hub for Cryptocurrency Fraud Darkhub: A Dark Web Hub for Cryptocurrency Fraud Cyber Security News
Microsoft to Restrict Windows 11 Auto Installs Due to RCE Flaw Microsoft to Restrict Windows 11 Auto Installs Due to RCE Flaw Cyber Security News
Claude Code Introduces Remote Terminal Control via Mobile Claude Code Introduces Remote Terminal Control via Mobile Cyber Security News
Pig-Butchering Scams Operators Scaled Their Operations with The Support of AI-Assistants Pig-Butchering Scams Operators Scaled Their Operations with The Support of AI-Assistants Cyber Security News
2025-8088 – WinRAR 0-Day Path Traversal Vulnerability Exploited to Execute Malware 2025-8088 – WinRAR 0-Day Path Traversal Vulnerability Exploited to Execute Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Teams Restores Services After Outage
  • Gitea Vulnerability Exploited in Cryptojacking Attack
  • CoreRAT Malware Empowers Hackers with Full System Control
  • OpenSSL Vulnerabilities Pose Risks to Servers
  • CISA Alerts on Active Gitea Vulnerability Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Teams Restores Services After Outage
  • Gitea Vulnerability Exploited in Cryptojacking Attack
  • CoreRAT Malware Empowers Hackers with Full System Control
  • OpenSSL Vulnerabilities Pose Risks to Servers
  • CISA Alerts on Active Gitea Vulnerability Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark