Abyssos Modular RAT Technical Analysis
Score: 8/10

Abyssos Modular RAT Technical Analysis

Abyssos is a new modular C++ RAT utilizing LLVM-based obfuscation and a custom TCP protocol to perform credential theft, remote access via VNC, and network reconnaissance.

Executive Summary

In late June 2026, Zscaler ThreatLabz identified Abyssos, a new modular remote administration tool (RAT) written in C++. This malware is in active development, characterized by its use of sophisticated intermediate representation (IR) passes—likely via open-source LLVM obfuscators like Pluto—to thwart binary analysis. Abyssos supports a wide range of post-exploitation activities including file exfiltration, keylogging, and browser session hijacking through a custom Hidden VNC (HVNC) implementation.

The malware's technical sophistication is evident in its initialization phase, which uses CRC32 checksums for dynamic API loading and specific mutex naming conventions to manage execution integrity. It employs a custom TCP protocol encrypted with AES-GCM for command-and-control (C2) communication. Its modular architecture allows it to download external components for specific tasks such as domain controller discovery and vulnerability scanning, making it a versatile tool for persistent access and internal lateral movement.

Abyssos represents a significant threat due to its evasive nature and comprehensive capability set. Its ability to inject cookies into debugging sessions of modern browsers (Chrome, Edge, Brave) directly facilitates session hijacking, bypassing traditional multi-factor authentication. Organizations should prioritize monitoring for the specific anti-analysis behaviors and network patterns associated with this evolving threat.

Key Details

Threat Name

Abyssos Modular RAT

Affects

—

Adversary

—

Malware/Tools

Abyssos, KEYLOGGER, RECOVERY, RECOVERY_GECKO, DCFINDER, VULNSCAN, ELEVATE_SYS_TOKEN, GRABCOOKIES, Win64.PWS.Abyssos

Report Score

8out of 10
Quality Score
Good
IOC Quality7
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure10
Technical Depth9

Sources