Abyssos: Technical Analysis of a New Modular RAT
Brief
Introduction In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC.
Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security products. In this blog post, ThreatLabz provides a technical analysis of Abyssos, including its core features, configuration, obfuscation, network communication protocol, and capabilities.
Key TakeawaysIn late June 2026, ThreatLabz identified a new malware family, Abyssos, which provides remote administration capabilities. Abyssos uses different intermediate representation (IR) passes, most likely using a publicly available LLVM obfuscator (e. g.
