Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access
Brief
A new remote access trojan called Abyssos lets attackers control infected Windows systems.
The malware can steal credentials, collect files, and open remote viewing sessions, while its modular design allows operators to add functions after an infection.
Abyssos appeared in late June 2026 and remains in development. Its operators can issue commands through an encrypted connection, gather details about the victim computer, and retrieve modules.
The research does not identify a confirmed initial delivery method, leaving the campaign’s entry point unclear. No specific lure or exploit was identified. Researchers at Zscaler identified the malware and tracked it as Abyssos.
Zscaler said in a report shared with Cyber Security News (CSN) that they found several versions and changing protections, suggesting the developers are actively refining it to make analysis and detection more difficult.
