← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 12, 2026 · 11:16via CyberPress

New Abyssos RAT Hijacks Browser Sessions, Steals Credentials and Gives Attackers Remote VNC Access

Brief

Abyssos operates as a post-exploitation framework. Once attackers gain access to a device, they can use the RAT to explore files , collect credentials, monitor activity, execute commands, download additional payloads, and remotely interact with the victim system.

One of Abyssos’ most concerning features is hidden virtual network computing, or HVNC . This capability allows attackers to open and control applications in an invisible desktop session that is separate from the victim’s visible screen.

Using commands such as HVNC_START , attackers can launch a hidden VNC session and run applications including Chrome, Microsoft Edge, Firefox, Brave, Opera, Vivaldi, PowerShell, Command Prompt, File Explorer, and multiple email clients.

Abyssos RAT Hijacks Browser Sessions

Abyssos can also clone browser data.

Read more on CyberPress