# Abyssos: New Modular C++ RAT with Hidden VNC Browser Session Hijacking, UAC Bypass and Downloadable Plugins

> Zscaler ThreatLabz analyzes Abyssos, a new modular Windows remote administration tool written in C++ and first identified in late June 2026, still under active development. It offers credential and cookie theft, file exfiltration, hidden VNC with browser session hijacking, keylogging, clipboard interception, UAC bypass and C2-downloaded plugins over a custom AES-GCM encrypted TCP protocol.

- **Published:** 2026-08-10T00:00:00Z
- **Last reviewed:** 2026-08-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2994
- **ID:** TL-2026-2994
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In late June 2026 Zscaler ThreatLabz identified a previously undocumented malware family, tracked as Abyssos: a modular remote administration tool (RAT) written in C++. Multiple builds have been observed (v1.1F/2.1F and v2.4F per the report), each with different LLVM intermediate-representation obfuscation passes that ThreatLabz assesses (medium-to-high confidence) were produced with a public LLVM obfuscator such as Pluto: control-flow flattening, bogus control flow with opaque predicates, constant integer encryption and stack-based string obfuscation. Newer builds drop some anti-analysis checks, indicating active iteration.

On start Abyssos resolves Windows APIs dynamically (CRC32 export checks) and creates a mutex of the form Global\[UUID4] with an _Admin or _User suffix; the --elevated command-line parameter forces the _Admin suffix regardless of actual privileges. Earlier builds perform anti-analysis: CPUID hypervisor detection (VMware, KVM, Xen, VirtualBox) and termination when VM-related processes such as vmtoolsd.exe, VBoxService.exe, xenservice.exe or qemu-ga.exe are present. The implant registers with its C2 using a pipe-delimited HELLO message carrying CPU architecture, computer name, username, integrity level, public IP, country and version string (e.g. v2.4F), then keeps a dedicated network thread that pings the C2 at intervals.

C2 traffic uses a custom TCP protocol. Each packet carries a 4-byte size, a flag byte, a 12-byte IV, the AES-GCM ciphertext and a 16-byte tag, encrypted with a hardcoded 32-byte key; command parameters are pipe-delimited (e.g. PM_KILL|1234). More than 40 commands are supported: hidden-desktop VNC (HVNC_START/STOP/INPUT, default 1920x1080), HVNC_CLONE_START which copies browser profile data to a 'fontconfigs' folder in the temp directory, HVNC_PROG which launches Chrome, Firefox, Edge, Brave, Vivaldi, Opera, Internet Explorer, Thunderbird, eM Client or Foxmail within the hidden session, and chrome_cdp which starts Chrome with remote debugging port 9222 and injects stolen cookies from fontconfigs\cookies.json through the Chrome DevTools Protocol (Network.setCookie over WebSocket). Other commands cover clipboard interception (polled every second), keylogger log retrieval from windows_update_cache.json, a file grabber filtering on directory, extension and size, process management (PM_*), TCP/UDP connection monitoring every two seconds (PF_*), file management with ZIP archiving and upload/download (FM_*), hosts-file edits (DNS_ADD/DNS_DEL), remote cmd.exe shell (C2CMD), screen recording (REMOTEDESKTOP_*), system information, power control and self-deletion through a ping-based delayed command. UAC bypass is available through UAC_BYPASS_FODHELPER (fodhelper binary) and UAC_BYPASS_ICMLUAUTIL (ICMLuaUtil COM interface). Payload-execution commands include EXECURL (download, execute, delete after 5 seconds), EXECURL_AES_HOL (AES-CBC encrypted shellcode injected into a named process), EXECLOCAL_HEX, EXECLOCAL_AES_HOL and AESHOL_DLL.

Abyssos is extended with plugins downloaded from the C2, decrypted with XOR or AES-CBC using the key '1234567890abcdef' and stored in %TEMP% under prefixed filenames: KEYLOGGER (klog_), RECOVERY and RECOVERY_GECKO (Chrome and Firefox credential recovery), GRABCOOKIES (browser cookies, reads %TEMP%\fontconfigs\), DCFINDER (domain controller discovery, export GetDCFinderText), VULNSCAN (export GetVulnScanJson), ELEVATE_SYS_TOKEN (privilege escalation to SYSTEM token), DATASCAN (datascan.png then ds_ prefix), RDPWRAP (RDP wrapper integration, export GetRdpWrapText), HDRPFILE, and SENDTXT/SENDTXT2. The report does not describe the initial delivery vector, persistence mechanism, attribution or victim sectors, and gives no C2 ports. Zscaler detects it as Win64.PWS.Abyssos.

## MITRE ATT&CK

- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
- T1134.001 Access Token Manipulation: Token Impersonation/Theft
- T1055 Process Injection
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1027 Obfuscated Files or Information
- T1070.004 Indicator Removal: File Deletion
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1056.001 Input Capture: Keylogging
- T1185 Browser Session Hijacking
- T1005 Data from Local System
- T1082 System Information Discovery
- T1057 Process Discovery
- T1219 Remote Access Tools
- T1095 Non-Application Layer Protocol
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1113 Screen Capture
- T1560 Archive Collected Data
- T1074.001 Data Staged: Local Data Staging
- T1049 System Network Connections Discovery
- T1033 System Owner/User Discovery
- T1018 Remote System Discovery
- T1140 Deobfuscate/Decode Files or Information

## Sources

- [Abyssos: Technical Analysis of a New Modular RAT (Zscaler ThreatLabz)](https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat)
- [Zscaler Threat Library: Win64.PWS.Abyssos](https://threatlibrary.zscaler.com/threats/f6a3ea49-b9b9-41a3-8966-9bb87f88d876)
- [Zscaler ThreatLabz Security Research](https://threatlabz.zscaler.com/)
- [Pluto LLVM obfuscator (suspected obfuscation tooling)](https://github.com/bluesadi/Pluto)
- [RDP Wrapper Library (basis of the RDPWRAP module)](https://github.com/stascorp/rdpwrap)
- [Abyssos: Technical Analysis of a New Modular RAT (mirror)](https://www.hendryadrian.com/?p=109572)
- [Abyssos Modular RAT Technical Analysis (detections.ai intel exchange)](https://detections.ai/intel-exchange/019ff129-6745-766c-9611-532fefb3de36)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2994
