{"id":10416,"date":"2026-02-05T10:00:55","date_gmt":"2026-02-05T10:00:55","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/05\/new-desckvb-rat-with-multi-stage-infection-chain-and-plugin-based-architecture\/"},"modified":"2026-02-05T10:00:55","modified_gmt":"2026-02-05T10:00:55","slug":"new-desckvb-rat-with-multi-stage-infection-chain-and-plugin-based-architecture","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/05\/new-desckvb-rat-with-multi-stage-infection-chain-and-plugin-based-architecture\/","title":{"rendered":"New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture"},"content":{"rendered":"<p>    New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated new threat has surfaced in the wild, identified as the DesckVB RAT version 2.9. This modular Remote Access Trojan, built on the .NET framework, has been observed in active malware campaigns throughout early 2026. <\/p>\n<p>Unlike simple backdoors, this threat demonstrates a high level of operational maturity, designed to establish persistent control over compromised systems while evading traditional defense mechanisms.<\/p>\n<p>The malware initiates its attack through a highly <a href=\"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/\" id=\"112724\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscated<\/a> Windows Script Host (WSH) JavaScript file. <\/p>\n<p>This initial stager performs critical setup tasks, such as copying itself to public user directories and executing via the wscript engine to mask its activity. <\/p>\n<p>By leveraging native Windows components, the attackers can blend their malicious traffic with legitimate system processes, complicating detection efforts for security teams.<\/p>\n<p>GitHub analysts noted that this initial activity is merely a gateway, setting the stage for a more potent payload. <\/p>\n<p>Following the initial execution, the infection chain transitions into a <a href=\"https:\/\/cybersecuritynews.com\/windows-powershell-0-day-vulnerability\/\" id=\"135740\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> stage that performs rigorous anti-analysis checks. <\/p>\n<p>It verifies internet connectivity and scans for debugging tools, ensuring the environment is safe before downloading the core malicious components. This careful validation prevents the malware from executing in <a href=\"https:\/\/cybersecuritynews.com\/simplify-malware-sandbox-config\/\" id=\"61834\" target=\"_blank\" rel=\"noreferrer noopener\">sandboxes<\/a>.<\/p>\n<p>The impact of DesckVB RAT lies in its stability and stealth. By using a fileless .NET loader, the malware executes directly in memory without leaving a physical footprint on the disk. <\/p>\n<p>This \u201cliving off the land\u201d approach allows it to bypass many static file scanning defenses, making <a href=\"https:\/\/cybersecuritynews.com\/forensic-analysis-in-cybersecurity\/\" id=\"108812\" target=\"_blank\" rel=\"noreferrer noopener\">forensic analysis<\/a> significantly more challenging for incident responders.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-modular-plugin-ecosystem\"><strong>Modular Plugin Ecosystem<\/strong><\/h2>\n<p>The most defining feature of DesckVB RAT is its robust plugin-based architecture, which allows operators to extend capabilities dynamically. <\/p>\n<p>Instead of bundling every malicious function into a single executable, the attackers can selectively deploy specific modules post-compromise based on the target\u2019s value. <\/p>\n<p>Validated plugins include a comprehensive keylogger that tracks active windows, a webcam streamer using DirectShow, and an antivirus enumerator that reports installed security products. <\/p>\n<p>These modules are delivered via a custom TCP protocol that uses distinct delimiters to manage payloads. <\/p>\n<p>This flexibility transforms the <a href=\"https:\/\/cybersecuritynews.com\/arsink-rat-attacking-android-devices\/\" id=\"141234\" target=\"_blank\" rel=\"noreferrer noopener\">RAT<\/a> from a simple backdoor into a versatile espionage tool, capable of adapting to various operational needs without requiring a complete re-infection of the host system.<\/p>\n<p>Security professionals are advised to focus on behavioral detection to mitigate this threat. <\/p>\n<p>Monitoring for unusual wscript.exe execution and <a href=\"https:\/\/cybersecuritynews.com\/windows-powershell-0-day-vulnerability\/\" id=\"135740\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> scripts building decimal byte arrays can provide early warning signs. <\/p>\n<p>Ensuring that endpoint detection systems are tuned to spot reflective code loading is also essential for effective mitigation against these evolving attacks.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-desckvb-rat-with-multi-stage-infection-chain\/\">New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-desckvb-rat-with-multi-stage-infection-chain\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture A sophisticated new threat has surfaced in the wild, identified as the DesckVB RAT version 2.9. This modular Remote Access Trojan, built on the .NET framework, has been observed in active malware campaigns throughout early 2026. Unlike simple backdoors, this threat demonstrates a high level [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10416","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10416"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10416"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10416\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10416"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10416"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10416"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}