Threat reportMalwareTL-2026-2994

Abyssos: New Modular C++ RAT with Hidden VNC Browser Session Hijacking, UAC Bypass and Downloadable Plugins

highACTIVE

Abyssos: New Modular C++ RAT with Hidden VNC Browser Session (TL-2026-2994), also tracked as Win64.PWS.Abyssos, is a high-severity malware campaign, first published 2026-08-10. It has no confirmed attribution, affects Microsoft Windows (64-bit), maps to 24 MITRE ATT&CK techniques (T1005, T1018, T1027), and is covered by 9 detection rules and 14 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-2994

Threat ID
TL-2026-2994
Also known as
Win64.PWS.Abyssos
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
14

Malware and tooling in Abyssos: New Modular C++ RAT with Hidden VNC Browser Session

Malware and tooling: Abyssos, Pluto LLVM obfuscator, RDP Wrapper, VNC

How Abyssos: New Modular C++ RAT with Hidden VNC Browser Session works

Zscaler ThreatLabz analyzes Abyssos, a new modular Windows remote administration tool written in C++ and first identified in late June 2026, still under active development. It offers credential and cookie theft, file exfiltration, hidden VNC with browser session hijacking, keylogging, clipboard interception, UAC bypass and C2-downloaded plugins over a custom AES-GCM encrypted TCP protocol.

In late June 2026 Zscaler ThreatLabz identified a previously undocumented malware family, tracked as Abyssos: a modular remote administration tool (RAT) written in C++. Multiple builds have been observed (v1.1F/2.1F and v2.4F per the report), each with different LLVM intermediate-representation obfuscation passes that ThreatLabz assesses (medium-to-high confidence) were produced with a public LLVM obfuscator such as Pluto: control-flow flattening, bogus control flow with opaque predicates, constant integer encryption and stack-based string obfuscation. Newer builds drop some anti-analysis checks, indicating active iteration.

On start Abyssos resolves Windows APIs dynamically (CRC32 export checks) and creates a mutex of the form Global\[UUID4] with an _Admin or _User suffix; the --elevated command-line parameter forces the _Admin suffix regardless of actual privileges. Earlier builds perform anti-analysis: CPUID hypervisor detection (VMware, KVM, Xen, VirtualBox) and termination when VM-related processes such as vmtoolsd.exe, VBoxService.exe, xenservice.exe or qemu-ga.exe are present. The implant registers with its C2 using a pipe-delimited HELLO message carrying CPU architecture, computer name, username, integrity level, public IP, country and version string (e.g. v2.4F), then keeps a dedicated network thread that pings the C2 at intervals.

C2 traffic uses a custom TCP protocol. Each packet carries a 4-byte size, a flag byte, a 12-byte IV, the AES-GCM ciphertext and a 16-byte tag, encrypted with a hardcoded 32-byte key; command parameters are pipe-delimited (e.g. PM_KILL|1234). More than 40 commands are supported: hidden-desktop VNC (HVNC_START/STOP/INPUT, default 1920x1080), HVNC_CLONE_START which copies browser profile data to a 'fontconfigs' folder in the temp directory, HVNC_PROG which launches Chrome, Firefox, Edge, Brave, Vivaldi, Opera, Internet Explorer, Thunderbird, eM Client or Foxmail within the hidden session, and chrome_cdp which starts Chrome with remote debugging port 9222 and injects stolen cookies from fontconfigs\cookies.json through the Chrome DevTools Protocol (Network.setCookie over WebSocket). Other commands cover clipboard interception (polled every second), keylogger log retrieval from windows_update_cache.json, a file grabber filtering on directory, extension and size, process management (PM_*), TCP/UDP connection monitoring every two seconds (PF_*), file management with ZIP archiving and upload/download (FM_*), hosts-file edits (DNS_ADD/DNS_DEL), remote cmd.exe shell (C2CMD), screen recording (REMOTEDESKTOP_*), system information, power control and self-deletion through a ping-based delayed command. UAC bypass is available through UAC_BYPASS_FODHELPER (fodhelper binary) and UAC_BYPASS_ICMLUAUTIL (ICMLuaUtil COM interface). Payload-execution commands include EXECURL (download, execute, delete after 5 seconds), EXECURL_AES_HOL (AES-CBC encrypted shellcode injected into a named process), EXECLOCAL_HEX, EXECLOCAL_AES_HOL and AESHOL_DLL.

Abyssos is extended with plugins downloaded from the C2, decrypted with XOR or AES-CBC using the key '1234567890abcdef' and stored in %TEMP% under prefixed filenames: KEYLOGGER (klog_), RECOVERY and RECOVERY_GECKO (Chrome and Firefox credential recovery), GRABCOOKIES (browser cookies, reads %TEMP%\fontconfigs\), DCFINDER (domain controller discovery, export GetDCFinderText), VULNSCAN (export GetVulnScanJson), ELEVATE_SYS_TOKEN (privilege escalation to SYSTEM token), DATASCAN (datascan.png then ds_ prefix), RDPWRAP (RDP wrapper integration, export GetRdpWrapText), HDRPFILE, and SENDTXT/SENDTXT2. The report does not describe the initial delivery vector, persistence mechanism, attribution or victim sectors, and gives no C2 ports. Zscaler detects it as Win64.PWS.Abyssos.

MITRE ATT&CK techniques used in TL-2026-2994

Collection

T1005 Data from Local System; T1056.001 Input Capture: Keylogging; T1074.001 Data Staged: Local Data Staging; T1113 Screen Capture; T1185 Browser Session Hijacking; T1560 Archive Collected Data

Discovery

T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1049 System Network Connections Discovery; T1057 Process Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1497.001 Virtualization/Sandbox Evasion: System Checks

Privilege Escalation

T1055 Process Injection; T1134.001 Access Token Manipulation: Token Impersonation/Theft; T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control

Execution

T1059.003 Command and Scripting Interpreter: Windows Command Shell

Command and Control

T1095 Non-Application Layer Protocol; T1219 Remote Access Tools; T1573.001 Encrypted Channel: Symmetric Cryptography

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Affected products and versions in Abyssos: New Modular C++ RAT with Hidden VNC Browser Session

  • Microsoft — Windows (64-bit)
    Vulnerable versions: Windows endpoints; browsers targeted: Chrome, Firefox, Edge, Brave, Vivaldi, Opera, Internet Explorer; mail clients: Thunderbird, eM Client, Foxmail

Remediation for Abyssos: New Modular C++ RAT with Hidden VNC Browser Session

Immediate actions

  • Block C2 IPs 213.145.86.42 and 209.99.184.223 at the perimeter and hunt historical egress to them
  • Hunt for the SHA256 hashes and for %TEMP% artifacts: windows_update_cache.json, fontconfigs\ folder, klog_/rcv_/rvg_/plg_/dcf_/vul_/gc_/ds_/rdp_ prefixed files
  • Alert on Global\<UUID4>_Admin / _User mutexes and processes launched with the --elevated parameter
  • Reset credentials and invalidate active browser sessions/cookies for users on hosts where Abyssos is confirmed

Workarounds

  • Set UAC to 'Always notify' and remove local administrator rights from standard users to hinder fodhelper/ICMLuaUtil bypasses

Longer-term hardening

  • Alert on browsers launched with --remote-debugging-port=9222 by non-browser parent processes
  • Monitor modifications of the Windows hosts file and fodhelper.exe / ICMLuaUtil COM UAC-bypass activity
  • Deploy EDR with behavioral coverage of hidden-desktop (HVNC) creation and cookie theft
  • Enforce phishing-resistant MFA and short session lifetimes to reduce value of stolen cookies

Timeline of Abyssos: New Modular C++ RAT with Hidden VNC Browser Session

  • Zscaler ThreatLabz identifies a new modular C++ RAT, tracked as Abyssos, in late June 2026
  • Report documents 35+ pipe-delimited C2 commands (HVNC, file/process management, clipboard, hosts edits, UAC bypass, payload execution) and ten C2-downloaded plugins
  • Zscaler Cloud Sandbox and threat library detect the family as Win64.PWS.Abyssos
  • Earlier version 2.1F (SHA256 ca94d954...) documented with C2 209.99.184.223, showing multiple builds with different LLVM obfuscation passes
  • Version 2.4F (SHA256 52b400c5...) analyzed as primary sample; C2 213.145.86.42; drops some anti-analysis checks seen in earlier builds
  • ThreatLabz publishes 'Abyssos: Technical Analysis of a New Modular RAT' with IOCs
  • detections.ai intel exchange republishes the analysis with ATT&CK mappings (e.g. T1548.002, T1539, T1115, T1219) and rates it high-quality

Sources cited for Abyssos: New Modular C++ RAT with Hidden VNC Browser Session

Detection coverage for TL-2026-2994

As of 2026-08-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2994 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2994

1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats