Top 10 Malware Threats Observed July 20-26, 2026
Key Takeaways Information stealers and Remote Access Trojans (RATs) continue to dominate the threat landscape, driven by accessible Malware-as-a-Service (MaaS) offerings. Vidar, AsyncRAT, and XWorm...
Key Takeaways
- Information stealers and Remote Access Trojans (RATs) continue to dominate the threat landscape, driven by accessible Malware-as-a-Service (MaaS) offerings.
- Vidar, AsyncRAT, and XWorm were the most frequently observed malware families, with XWorm and Formbook showing increased activity.
- Phishing remains the primary infection vector, often leveraging legitimate infrastructure and “living off the land” binaries (LOLBins) to bypass traditional defenses.
- Key vulnerabilities exploited include CVE-2017-11882 in Microsoft Equation Editor and CVE-2025-8088 in WinRAR.
- Organizations must implement layered security, including robust email filtering, patch management, process monitoring, and user behavior controls, to mitigate these pervasive threats.
Overview of Malware Trends: July 20-26, 2026
The latest analysis of malware submissions to public sandboxes reveals a consistent pattern in the tools most frequently encountered by cybersecurity professionals. This week’s data, spanning July 20-26, 2026, highlights the persistent threat posed by information stealers and Remote Access Trojans (RATs), underscoring the widespread availability and utility of Malware-as-a-Service (MaaS) offerings in the cybercriminal underground.
Table Of Content
- Key Takeaways
- Overview of Malware Trends: July 20-26, 2026
- Top 10 Malware Families by Uploads (July 20-26, 2026)
- Threat Family Profiles
- Vidar Stealer
- AsyncRAT
- XWorm
- Remcos RAT
- Stealc
- Lumma Stealer
- Formbook
- Quasar RAT
- AgentTesla
- DonutLoader
- Known Infection Vectors
- Known Tools and Living-off-the-Land Binaries Abused
- Targeted Industries
- Common Vulnerabilities Exploited (CVEs)
- Indicators of Compromise (IOCs)
- File Hashes
- Malicious Domains and URLs
- IP Addresses
Info-stealers such as Vidar, Stealc, and Lumma, alongside RATs like AsyncRAT, XWorm, Remcos, and Quasar, constitute the majority of observed threats. This dominance reflects a market where sophisticated malicious capabilities are readily accessible, enabling a broad range of cyberattacks.
Vidar led the weekly rankings with 235 total uploads, despite a decrease of 47 samples from the previous period. AsyncRAT was a close second, registering 214 uploads, a reduction of 60. Conversely, XWorm saw a notable uptick with 205 uploads, marking a rare weekly increase of 13 samples, which suggests renewed or expanded campaign activity.
Formbook and XWorm were the only malware families to exhibit an upward trend in upload counts this week. This rise is a critical indicator for defenders, as increasing submission rates often precede a surge in active campaigns exploiting new vulnerabilities or employing novel lures.
In contrast, AgentTesla and DonutLoader experienced the most significant declines, with 59 and 58 fewer samples, respectively. Despite these drops, both families remain prevalent components of commodity phishing kits, indicating their continued use in initial access operations.
Top 10 Malware Families by Uploads (July 20-26, 2026)
| Rank | Malware Family | Type | Total Uploads | Weekly Change |
|---|---|---|---|---|
| 1 | Vidar | Infostealer | 235 | -47 |
| 2 | AsyncRAT | RAT | 214 | -60 |
| 3 | XWorm | RAT | 205 | +13 |
| 4 | Remcos | RAT/Surveillanceware | 158 | -36 |
| 5 | Stealc | Infostealer | 126 | -44 |
| 6 | Lumma | Infostealer | 121 | -21 |
| 7 | Formbook | Infostealer | 113 | +41 |
| 8 | Quasar | RAT | 109 | -6 |
| 9 | AgentTesla | Infostealer/Keylogger | 108 | -59 |
| 10 | DonutLoader | Loader | 99 | -58 |
Threat Family Profiles
Vidar Stealer
Vidar, an information stealer derived from Arkei, operates as a malware-as-a-service (MaaS) offering. Its primary function is to harvest sensitive data, including browser credentials, cookies, two-factor authentication information, Tor Browser configurations, and cryptocurrency wallet details. Recent campaigns in 2026 have seen Vidar distributed through malvertising, leading to fake cracked-software downloads, and via trojanized GitHub repositories masquerading as legitimate developer tools. The payloads are often cleverly embedded within JPEG and TXT files for in-memory execution. A notable parallel campaign involves Vidar being delivered alongside the XMRig cryptominer, employing DLL sideloading through a Go-compiled fake MpClient.dll to evade detection.
AsyncRAT
AsyncRAT is a widely exploited open-source Remote Access Trojan (RAT) that enables adversaries to execute commands remotely, exfiltrate data, and conduct covert surveillance on Windows systems. Current campaigns abuse legitimate infrastructure, such as Dropbox links and TryCloudflare tunnels. The infection chain typically initiates with an LNK file, followed by JavaScript and batch scripts that ultimately deploy Python-based loaders while displaying a deceptive invoice PDF. Persistence is achieved via startup-folder batch scripts and code injection into explorer.exe. Regional campaigns have observed C2 traffic utilizing TCP ports 6606, 7707, and 8808.
XWorm
XWorm is a modular RAT, available through MaaS channels since 2022, offering a range of malicious capabilities including credential theft, keylogging, webcam access, DDoS attacks, and ransomware deployment plugins. The 2026 infection chain typically starts with phishing emails containing ZIP attachments, often disguised as payment confirmations. These attachments extract a malicious JavaScript loader that establishes persistence in the Startup folder and retrieves a Base64-encoded DLL appended to a JPEG file hosted on public image services. The payload is then injected into MSBuild.exe or Aspnet_compiler.exe via process hollowing for fileless execution. Newer variants have been observed exploiting the WinRAR flaw CVE-2025-8088 and CVE-2018-0802 in Excel to bypass detection.
Remcos RAT
Initially a legitimate remote administration tool, Remcos has been extensively misused as a surveillance-as-a-service RAT. Its capabilities include live webcam streaming, real-time keylogging, credential theft, and screen capture. The primary infection vector remains phishing emails containing malicious ZIP or LNK attachments, followed by text-based staging and the abuse of legitimate Microsoft Living-off-the-Land Binaries (LOLBins) like MSBuild.exe to evade detection. Education, professional services, and finance sectors in Latin America (Colombia, Brazil) and the U.S. are the most frequent targets, with C2 traffic often routed through Dynamic DNS providers such as DuckDNS. Additional insights into Remcos’ evolution can be found in Lumu’s analysis.
Stealc
Stealc is a modular, MaaS infostealer designed to target a wide array of sensitive data, including information from browsers, FTP clients, messaging applications, email clients, gaming platforms, and cryptocurrency wallets. Its V2 iteration introduced RC4 encryption for stolen data, enhancing its stealth. It propagates through various channels, including phishing attachments, malvertising, drive-by downloads, and compromised cracked software/keygen sites. Stealc is frequently observed bundled with other cybercrime services, such as Amadey.
Lumma Stealer
Lumma (LummaC2), a subscription-based MaaS infostealer, has re-emerged with more sophisticated tactics following a law enforcement takedown of its core infrastructure. Current delivery methods include deceptive CAPTCHA “ClickFix” pages that trick victims into executing malicious PowerShell commands via the Windows Run dialog. Other vectors involve trojanized GitHub repositories featuring AI-generated README files promoting game cheats, and coordinated YouTube video campaigns linking to malicious downloads. Trend Micro provides further details on Lumma Stealer’s return.
Formbook
Formbook is a long-standing data stealer and form-grabber, sold as MaaS since 2016. It offers capabilities such as keylogging, screenshot capture, credential theft, and the ability to stage additional malware. Recent campaigns leverage phishing emails with RAR attachments that abuse DLL sideloading, or obfuscated JavaScript embedded in PDFs. Older campaigns exploited CVE-2017-11882 in Microsoft Equation Editor through malicious Word documents. Aerospace, defense contractors, and manufacturing sectors in the U.S. and South Korea have been disproportionately targeted. More information on Formbook campaigns is available from Google Cloud.
Quasar RAT
Quasar is an open-source, C#-based RAT that provides attackers with extensive remote control over compromised systems, including registry editing, keylogging, password theft, and file exfiltration. It is commonly delivered via malicious RTF or Office documents that trigger PowerShell payload downloads. Newer variants utilize dual DLL sideloading techniques to drop and execute payloads without triggering standard detection mechanisms.
AgentTesla
AgentTesla is a .NET-based RAT and advanced keylogger that has been active since 2014. Its functionalities include clipboard logging, screen capture, and the theft of stored browser and email credentials. It is primarily delivered through phishing emails that exploit Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2017-8570. Exfiltrated data is typically sent via SMTP, FTP, or Telegram bot channels.
DonutLoader
DonutLoader is a shellcode-based loader that utilizes the “Donut” fileless execution framework to deploy secondary payloads, such as the PureLogs stealer, directly into memory. This approach helps avoid disk-based artifacts, enhancing stealth. Recent campaigns have employed “ClickFix”-style spoofed licensing websites, tricking victims into executing malicious PowerShell commands. These actions establish TCP-based C2 communications for data exfiltration and configuration retrieval. Further details on the Canndelta ClickFix campaign are available from Gurucul.
Known Infection Vectors
Phishing remains the most pervasive common denominator across all ten malware families, though the specific lures and payload staging techniques vary significantly depending on the malware family.
| Infection Vector | Malware Families Using It |
|---|---|
| Phishing email with ZIP/RAR archive attachment | AsyncRAT, XWorm, Remcos, Formbook |
| Malicious Office document (macro/exploit) | AgentTesla, Quasar, Formbook, Snake Keylogger |
| Malvertising / fake cracked software | Vidar, Stealc, Lumma |
| Trojanized GitHub repositories | Vidar, Lumma |
| Fake CAPTCHA / ClickFix PowerShell execution | Lumma, DonutLoader |
| LNK/JS/BAT multi-stage script chains | AsyncRAT, XWorm |
| PDF or image (JPEG) steganographic payloads | XWorm, Vidar |
| Dropbox/TryCloudflare abused infrastructure | AsyncRAT |
Known Tools and Living-off-the-Land Binaries Abused
Threat actors are increasingly leveraging legitimate, signed Windows utilities, known as Living-off-the-Land Binaries (LOLBins), to camouflage malicious activities within normal system operations and bypass signature-based detection.
- MSBuild.exe: Abused by XWorm and Remcos for reflective DLL injection and payload execution.
- Aspnet_compiler.exe: Utilized by XWorm for in-memory reflective DLL injection, as detailed by Trellix research.
- PowerShell (-nop, -ep bypass): Employed across XWorm, DonutLoader, and Lumma ClickFix chains for staged payload decryption and execution.
- wscript.exe / mshta.exe: Used to trigger JavaScript and HTA loaders in XWorm and Remcos campaigns.
- RegAsm.exe / RegSvcs.exe / InstallUtil.exe: Abused via process hollowing/injection by AgentTesla and Snake Keylogger.
- explorer.exe: A target for code injection in AsyncRAT campaigns, as highlighted in Trend Micro’s analysis.
- Python interpreter (legitimate installer): Deployed by AsyncRAT operators to run malicious scripts under a trusted runtime. Further details can be found in Trend Micro’s MDR analysis.
- Donut shellcode framework: Leveraged by DonutLoader for fileless, in-memory .NET assembly loading, as discussed by Gurucul.
Targeted Industries
| Industry | Malware Families Observed | Notes |
|---|---|---|
| Education & nonprofits | Remcos | Underfunded IT security, high-value data. See Lumu’s report. |
| Financial services | Remcos, AgentTesla | Credential and wire-fraud targeting. More insights from Lumu. |
| Aerospace & defense contractors | Formbook | High-value IP theft campaigns in US/South Korea. Referenced by Google Cloud. |
| Manufacturing | Formbook | Targeted via archive-based phishing. Additional information from Google Cloud. |
| Retail & hospitality | Snake Keylogger | Payment card and loyalty credential theft. RH-ISAC provides details. |
| Professional services & technology | Remcos, Stealc | MaaS-driven credential harvesting. |
| Government (regional) | AsyncRAT, general loaders | Hijacked government sites used as delivery channels. |
| SMBs and consumer users | Vidar, Lumma, Stealc | Malvertising and cracked-software targeting broad consumer base. |
Common Vulnerabilities Exploited (CVEs)
| CVE | Vulnerability | Exploited By |
|---|---|---|
| CVE-2017-11882 | Microsoft Equation Editor stack buffer overflow (RCE) | AgentTesla, Formbook |
| CVE-2017-8570 | Microsoft Office RCE via OLE object | AgentTesla |
| CVE-2018-0802 | Microsoft Office Equation Editor memory corruption | XWorm |
| CVE-2025-8088 | WinRAR path traversal leading to arbitrary code execution | XWorm |
Beyond these documented CVEs, most malware families rely on social engineering and the abuse of legitimate tools rather than novel zero-day exploits. This trend emphasizes that patch management alone is insufficient; robust user-behavior controls and strict macro/script restrictions are equally crucial for effective defense.
Indicators of Compromise (IOCs)
File Hashes
| Malware | Hash Type | Value |
|---|---|---|
| AsyncRAT | SHA1 (zip) | 55724b766dd1fe8bf9dd4cb7094b83b88d57d945 |
| AsyncRAT | SHA1 (url) | 4483561a49791a7cd684258e9f1623fe7dfba772 |
| AsyncRAT | SHA1 (lnk) | 0aa1b8fba8d7bd19a0064edfdf86c027da253644 |
| XWorm | MD5 (weaponized archive) | 2074283c9ccc441185cba631fcc8a234 |
| Stealc | MD5 (sample) | 9f34ab1c9d9351f59826b8d5c458a3d3 |
| Quasar | SHA-256 | cf7a24c9f2f9d85cc1ba4a11890087b82e38f39c8d194e808e9e6d82a188d3f0 |
| Quasar | SHA-256 | 14b573b7e3ff8ad4e1489a5c039532f16f9eff34ead1d299f97fb0badf0affdc |
| Formbook | SHA1 (MalVirt loader) | 15DB79699DCEF4EB5D731108AAD6F97B2DC0EC9C |
| Formbook | SHA1 (0onfirm .NET assembly) | 655D0B6F6570B5E07834AA2DD8211845B4B59200 |
| Formbook | SHA-256 (order0087.docx) | 93CF566C0997D5DCD1129384420E4CE59764BD86FDABAAA8B74CAF5318BA9184 |
| AgentTesla | MD5 (VBS file) | e2a4a40fe8c8823ed5a73cdc9a8fa9b9 |
| AgentTesla | SHA256 (VBS file) | e7a157ba1819d7af9a5f66aa9e161cce68d20792d117a90332ff797cbbd8aaa5 |
| AgentTesla | MD5 (final payload) | dd94daef4081f63cf4751c3689045213 |
| AgentTesla | MD5 (COVID doc sample) | 527142E25A8229D1DC910AF23CDB5256 |
| DonutLoader | SHA-256 | 0099deccd390e229895d0c508882632569f9533e42d33a675885ee7f4f5164f3 |
| DonutLoader | SHA-256 | 61b453cfedc6c67d9744b963bc3cabbee33f53606fdbf80da04bc3d4c93eb4fb |
| DonutLoader | SHA-256 | 9bb96fa6aee45120d14660506320932691310adef4353e684775f590a17c22fc |
| Snake Keylogger | MD5 | c79d8b7c07b992c6aa435e4101770f99 |
| Snake Keylogger | MD5 (ageless.exe) | f8410bcd14256d6d355d7076a78c074f |
| Snake Keylogger | MD5 (ageless.vbs) | 77f8db41b320c0ba463c1b9b259cfd1b |
| Quasar (ISO sample) | MD5 | e4eb623a0f675960acb002d225c6f1d6 |
| Quasar (eBill loader) | MD5 | B625C18E177D5BEB5A6F6432CCF46FB3 |
Malicious Domains and URLs
| Malware | Domain / URL |
|---|---|
| AsyncRAT | inventory-card-thumbzilla-ip[.]trycloudflare[.]com |
| AsyncRAT | mercy-synopsis-notify-motels[.]trycloudflare[.]com/ma[.]zip |
| AsyncRAT | sufficiently-points-est-minimize[.]trycloudflare[.]com/ma[.]zip |
| AsyncRAT (regional) | ck44jili[.]com, mail.emb666[.]com |
| XWorm | kolanga[.]cc |
| Remcos | Nrmlogistics[.]ro (loader) |
| Remcos | Dentalux202[.]ydns[.]eu (C2) |
| Lumma | futureddospzmvq[.]shop, writerospzm[.]shop, mennyudosirso[.]shop |
| Lumma | deallerospfosu[.]shop, quialitsuzoxm[.]shop, complaintsipzzx[.]shop |
| Formbook | www.togsfortoads[.]com, www.popimart[.]xyz |
| Snake Keylogger | varders[.]kozow[.]com:8081, aborters[.]duckdns[.]org:8081 |
| Snake Keylogger | anotherarmy[.]dns[.]army:8081 |
| DonutLoader | canndelta[.]com |
| DonutLoader | 158.94.208.104/x7GkP2mQ9zL4/my_new_l.bin |
| Formbook (image relay) | www2[.]0zz0[.]com/2025/02/02/10/709869215.png |
IP Addresses
| Malware | IP Address |
|---|---|
| XWorm | 204.10.160.190 (C2, TCP port 7003) |
| Remcos | 107.172.139.23, 193.230.215.22, 94.198.96.165 |
| Lumma | 144.76.173[.]247, 45.9.74[.]78, 77.73.134[.]68 |
| Lumma | 82.117.255[.]127, 82.118.23[.]50 |
| AgentTesla | 79.110.48[.]52, 193.42.33.51 |
| Snake Keylogger | 89[.]208[.]29[.]130, 69[.]55[.]5[.]
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.