Abyssos: Technical Analysis of a New Modular RAT
Zscaler ThreatLabz analyzes Abyssos, a new modular C++ RAT offering credential theft, file exfiltration, and VNC-based remote access.
Zscaler ThreatLabz identified a new malware family tracked as Abyssos in late June 2026. Abyssos is a modular remote administration tool (RAT) written in C++ that supports credential theft, file exfiltration, and remote access via VNC. The malware is under active development, with multiple version numbers and obfuscation passes designed to evade security products. The analysis covers its core features, configuration, obfuscation, and network communication protocol.
- New modular RAT family Abyssos identified in late June 2026
- Written in C++ with credential theft, file exfiltration, VNC access
- Actively developed with multiple versions and obfuscation passes
- Obfuscation designed to evade security product detections
Introduction In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security products.In this blog post, ThreatLabz provides a technical analysis of Abyssos, including its core features, configuration, obfuscation, network communication protocol, and capabilities. Key TakeawaysIn late June 2026, ThreatLabz identified a new malware…
This source does not provide full text. Read it at zscaler.com.