New Abyssos RAT Hijacks Browser Sessions, Steals Credentials and Gives Attackers Remote VNC Access
Brief
Abyssos operates as a post-exploitation framework. Once attackers gain access to a device, they can use the RAT to explore files , collect credentials, monitor activity, execute commands, download additional payloads, and remotely interact with the victim system.
One of Abyssos’ most concerning features is hidden virtual network computing, or HVNC . This capability allows attackers to open and control applications in an invisible desktop session that is separate from the victim’s visible screen.
Using commands such as HVNC_START , attackers can launch a hidden VNC session and run applications including Chrome, Microsoft Edge, Firefox, Brave, Opera, Vivaldi, PowerShell, Command Prompt, File Explorer, and multiple email clients.
Abyssos RAT Hijacks Browser Sessions
Abyssos can also clone browser data.
