Patchwork-linked StreamSpy Trojan adds WebSocket and HTTP C2
Malware Activity
Summary
Hide ▲
Show ▼
QiAnXin linked Patchwork/Maha Grass to StreamSpy, a previously undocumented Windows RAT delivered through OPS-VII-SIR.zip and Annexure.exe. The malware uses WebSocket and HTTP for command and control, and can persist through the Windows Registry, scheduled tasks, or a Startup LNK file while harvesting system information, transferring files, and running shell commands. Separately, ReversingLabs described pkr_mtsi as a flexible Windows malware packer/loader first seen on April 24 2025. That loader was used in malvertising and SEO-poisoning campaigns to push trojanized installers and deliver Oyster, Vidar, Vanguard Stealer and Supper.
Related Happenings
Open-OSS/privacy-filter Hugging Face infostealer activity
Malware Activity
H score69
First: 11.05.2026 10:05
Last: 11.05.2026 10:05
Sources 1
About this happening:
A malicious Hugging Face repository called Open-OSS/privacy-filter impersonated OpenAI's Privacy Filter and delivered a Rust-based information stealer to Windows...
Open-OSS/privacy-filter Hugging Face infostealer activity
Malware ActivityAbout this happening: A malicious Hugging Face repository called Open-OSS/privacy-filter impersonated OpenAI's Privacy Filter and delivered a Rust-based information stealer to Windows...
Snow malware suite deployment by UNC6692
Malware Activity
H score29
First: 25.04.2026 18:07
Last: 25.04.2026 18:07
Sources 1
About this happening:
UNC6692 has deployed the Snow malware suite through social engineering, creating a stealthy path to credential theft and domain compromise. The operation uses em...
Snow malware suite deployment by UNC6692
Malware ActivityAbout this happening: UNC6692 has deployed the Snow malware suite through social engineering, creating a stealthy path to credential theft and domain compromise. The operation uses em...
A0Backdoor malware deployed through signed MSI sideloading and DNS MX C2
Malware Activity
H score22
First: 10.03.2026 00:50
Last: 10.03.2026 00:50
Sources 1
About this happening:
The A0Backdoor malware was deployed on Windows endpoints through digitally signed MSI installers and DLL sideloading, giving the operators a stealthier path to exe...
A0Backdoor malware deployed through signed MSI sideloading and DNS MX C2
Malware ActivityAbout this happening: The A0Backdoor malware was deployed on Windows endpoints through digitally signed MSI installers and DLL sideloading, giving the operators a stealthier path to exe...
MIMICRAT (aka AstarionRAT) ClickFix-delivered RAT activity
Malware Activity
H score22
First: 20.02.2026 13:55
Last: 20.02.2026 13:55
Sources 1
About this happening:
The MIMICRAT (aka AstarionRAT) malware has been disclosed as a ClickFix-delivered RAT that enables Windows token impersonation and SOCKS5 tunneling, increasing the...
MIMICRAT (aka AstarionRAT) ClickFix-delivered RAT activity
Malware ActivityAbout this happening: The MIMICRAT (aka AstarionRAT) malware has been disclosed as a ClickFix-delivered RAT that enables Windows token impersonation and SOCKS5 tunneling, increasing the...
ClickFix compromised-site MIMICRAT campaign
Campaign
H score37
First: 20.02.2026 13:55
Last: 20.02.2026 13:55
Sources 1
About this happening:
The ClickFix campaign is abusing compromised legitimate sites to deliver the MIMICRAT remote access trojan through a multi-stage infection chain, widening risk acr...
ClickFix compromised-site MIMICRAT campaign
CampaignAbout this happening: The ClickFix campaign is abusing compromised legitimate sites to deliver the MIMICRAT remote access trojan through a multi-stage infection chain, widening risk acr...
Timeline
-
07.01.2026 18:45 1 articles · 6mo ago
ReversingLabs first observes pkr_mtsi malware loader
Initial DisclosureReversingLabs identified pkr_mtsi as a flexible Windows malware packer and loader first seen on April 24 2025, used in large-scale malvertising and SEO-poisoning campaigns to distribute trojanized installers masquerading as legitimate software and deliver Oyster, Vidar, Vanguard Stealer and Supper.
Show sources
- Versatile Malware Loader pkr_mtsi Delivers Diverse Payloads — www.infosecurity-magazine.com — 07.01.2026 18:45
-
02.01.2026 15:52 2 articles · 6mo ago
Patchwork-linked StreamSpy Trojan adds WebSocket and HTTP C2
Initial DisclosureQiAnXin associated Patchwork, also called Maha Grass, with StreamSpy, a previously undocumented Windows RAT distributed through OPS-VII-SIR.zip and Annexure.exe that uses WebSocket and HTTP for command-and-control, supports persistence through the Windows Registry, scheduled tasks, or a Startup LNK file, and can harvest system information, transfer files, execute shell commands, delete or rename files, and enumerate folders; the same Annexure.exe sample was also flagged as ShadowAgent in November 2025.
Show sources
- Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia — thehackernews.com — 02.01.2026 15:52
- Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia — thehackernews.com — 02.01.2026 15:52