In early 2026 the Trellix ARC team identified and analysed an active DarkCrystal RAT (DCRat) campaign. They unpack each stage of the infection chain, revealing how attackers combine stealth, sideloading, and process injection to establish long-term access. https://t.co/kzVYyy5uE2
Threat alert 🚨 XWorm detections have surged 4.3x YoY. For just $500, threat actors use reflective DLL injection and LotL tactics to bypass legacy EDR.
High-impact RATs are no longer high-cost.
Read our full technical analysis. https://t.co/EkTna01mcU
Remcos RAT goes fileless.
🛡️By subverting trusted Windows processes and executing via RAM-only injection, it bypasses traditional AV and leaves no disk footprint. A masterclass in forensic evasion.
Full analysis: https://t.co/cjEe4wzqNl
How does Lumma Stealer evade detection & steal your data? 🤔 Our analysis covers its infection chain, obfuscation, anti-sandbox & more in our latest blog: https://t.co/zTodUCxnlo