Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st)
2026-06-01T01:23:48Z•1a128d8e1c0e0379aa68120e0308fff3383cafdc59653f9190d88d51f8214f65
akiracredential-theftdshieldforensicsmalwaremicrosoft-accessnetsupportpodcastransomwareratrsssans-iscstealertelemetrythreat-intelvbayarayara-x
What happened
SANS ISC diary RSS feed (items dated May 25–Jun 1, 2026) summarizing multiple posts: an Unidentified RAT observed pushing NetSupport RAT; YARA‑X 1.17.0 release (performance improvements and a bugfix); analysis of a year of files uploaded to DShield sensors (telemetry/Kibana); an Akira ransomware kill‑chain reconstruction focused on pre‑impact perimeter and Windows event logs; a possible ACR stealer page impersonating Claude; a note on Microsoft Access VBA containing code; and several ISC Stormcast podcast entries. Topics cover malware/RAT activity, credential/stealer threats, ransomware forenS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 1a128d8e1c0e0379aa68120e0308fff3383cafdc59653f9190d88d51f8214f65
- Enrichment time
- 2026-06-01T01:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.