MALFEX hid a RAT and stealer in PNG files via npm postinstall - two packages still installable. https://intel.threadlinqs.com/threat/TL-2026-2801 #ThreatIntel #Overlord #movinlike #Rakhni

MALFEX hid a RAT and stealer in PNG files via npm postinstall - two packages still installable. https://intel.threadlinqs.com/threat/TL-2026-2801 #ThreatIntel #Overlord #movinlike #Rakhni
SectopRAT variant hides inside legit audio software via a tampered DLL - AES C2 from byte one. https://intel.threadlinqs.com/threat/TL-2026-2646 #ThreatIntel #SectopRAT #ArechClient2 #Rakhni
Lua loader hides in fake .ttf font files - fileless RATs via VEH-encrypted shellcode. https://intel.threadlinqs.com/threat/TL-2026-2402 #ThreatIntel #Rakhni #Agent #XWorm