Find notable cyber news and cases, enriched with sources, timelines, and signals.

Patchwork-linked StreamSpy Trojan adds WebSocket and HTTP C2

Malware Activity
First reported
Last updated
Happening score
H score 23
2 unique sources, 2 articles

Summary

Hide ▲

QiAnXin linked Patchwork/Maha Grass to StreamSpy, a previously undocumented Windows RAT delivered through OPS-VII-SIR.zip and Annexure.exe. The malware uses WebSocket and HTTP for command and control, and can persist through the Windows Registry, scheduled tasks, or a Startup LNK file while harvesting system information, transferring files, and running shell commands. Separately, ReversingLabs described pkr_mtsi as a flexible Windows malware packer/loader first seen on April 24 2025. That loader was used in malvertising and SEO-poisoning campaigns to push trojanized installers and deliver Oyster, Vidar, Vanguard Stealer and Supper.

Related Happenings

Open-OSS/privacy-filter Hugging Face infostealer activity

Malware Activity
H score69 First: 11.05.2026 10:05 Last: 11.05.2026 10:05 Sources 1

About this happening: A malicious Hugging Face repository called Open-OSS/privacy-filter impersonated OpenAI's Privacy Filter and delivered a Rust-based information stealer to Windows...

Snow malware suite deployment by UNC6692

Malware Activity
H score29 First: 25.04.2026 18:07 Last: 25.04.2026 18:07 Sources 1

About this happening: UNC6692 has deployed the Snow malware suite through social engineering, creating a stealthy path to credential theft and domain compromise. The operation uses em...

A0Backdoor malware deployed through signed MSI sideloading and DNS MX C2

Malware Activity
H score22 First: 10.03.2026 00:50 Last: 10.03.2026 00:50 Sources 1

About this happening: The A0Backdoor malware was deployed on Windows endpoints through digitally signed MSI installers and DLL sideloading, giving the operators a stealthier path to exe...

MIMICRAT (aka AstarionRAT) ClickFix-delivered RAT activity

Malware Activity
H score22 First: 20.02.2026 13:55 Last: 20.02.2026 13:55 Sources 1

About this happening: The MIMICRAT (aka AstarionRAT) malware has been disclosed as a ClickFix-delivered RAT that enables Windows token impersonation and SOCKS5 tunneling, increasing the...

ClickFix compromised-site MIMICRAT campaign

Campaign
H score37 First: 20.02.2026 13:55 Last: 20.02.2026 13:55 Sources 1

About this happening: The ClickFix campaign is abusing compromised legitimate sites to deliver the MIMICRAT remote access trojan through a multi-stage infection chain, widening risk acr...

Timeline

  1. 07.01.2026 18:45 1 articles · 6mo ago

    ReversingLabs first observes pkr_mtsi malware loader

    Initial Disclosure

    ReversingLabs identified pkr_mtsi as a flexible Windows malware packer and loader first seen on April 24 2025, used in large-scale malvertising and SEO-poisoning campaigns to distribute trojanized installers masquerading as legitimate software and deliver Oyster, Vidar, Vanguard Stealer and Supper.

    Show sources
  2. 02.01.2026 15:52 2 articles · 6mo ago

    Patchwork-linked StreamSpy Trojan adds WebSocket and HTTP C2

    Initial Disclosure

    QiAnXin associated Patchwork, also called Maha Grass, with StreamSpy, a previously undocumented Windows RAT distributed through OPS-VII-SIR.zip and Annexure.exe that uses WebSocket and HTTP for command-and-control, supports persistence through the Windows Registry, scheduled tasks, or a Startup LNK file, and can harvest system information, transfer files, execute shell commands, delete or rename files, and enumerate folders; the same Annexure.exe sample was also flagged as ShadowAgent in November 2025.

    Show sources