Executive Summary
In late June 2026, Zscaler ThreatLabz identified Abyssos, a new modular remote administration tool (RAT) written in C++. This malware is in active development, characterized by its use of sophisticated intermediate representation (IR) passes—likely via open-source LLVM obfuscators like Pluto—to thwart binary analysis. Abyssos supports a wide range of post-exploitation activities including file exfiltration, keylogging, and browser session hijacking through a custom Hidden VNC (HVNC) implementation.
The malware's technical sophistication is evident in its initialization phase, which uses CRC32 checksums for dynamic API loading and specific mutex naming conventions to manage execution integrity. It employs a custom TCP protocol encrypted with AES-GCM for command-and-control (C2) communication. Its modular architecture allows it to download external components for specific tasks such as domain controller discovery and vulnerability scanning, making it a versatile tool for persistent access and internal lateral movement.
Abyssos represents a significant threat due to its evasive nature and comprehensive capability set. Its ability to inject cookies into debugging sessions of modern browsers (Chrome, Edge, Brave) directly facilitates session hijacking, bypassing traditional multi-factor authentication. Organizations should prioritize monitoring for the specific anti-analysis behaviors and network patterns associated with this evolving threat.
