216.73.216.226

Understanding CyberEYE RAT Builder: Capabilities and Implications

· Published 13/06/2025 07:40 · Modified 13/06/2025 08:49

Export JSON

Essential information

Published
13/06/2025 07:40
Modified
13/06/2025 08:49
Tags
2025-06-13 anti-analysis credential-theft cybereye data exfiltration persistence rat telegram telegramrat windows defender evasion
Related entities
13 techniques (mitre), 2 malware

Description

is a modular, .NET-based Remote Access Trojan that utilizes for Command and Control, eliminating the need for attackers to maintain their own infrastructure. It offers a wide array of surveillance and data theft capabilities, including keylogging, file grabbing, and clipboard hijacking. The malware employs advanced defense evasion techniques, disabling Windows Defender through PowerShell and registry manipulations. Its modules harvest browser credentials, Wi-Fi passwords, gaming profiles, and session data from various applications. The builder framework allows adversaries to customize payloads, making it accessible to less technically skilled threat actors. 's mechanisms, features, and use of public messaging platforms for C2 make it a significant threat to both consumers and enterprises.

External references