CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
This post is the result of an investigation into a case we worked on, in which we traced a loader chain that ended where we didn't expect.
This post is the result of an investigation into a case we worked on, in which we traced a loader chain that ended where we didn't expect.
In light of the water-sector activity described below, we've increased monitoring for related indicators of compromise across our client environments. Please contact your LevelBlue account team with questions specific to your environment.
Remote access trojans (RATs) are legacy threats that continue to evolve alongside an expanding and ever-changing threat landscape. Following our recently published articles about novel and notable RATs, including KarstoRAT, the latest version of ClickFix, and ClickFix’s macOS variant, we analyzed QuimaRAT, a novel Java-based RAT that targets Windows, Linux, and macOS environments and is currently being sold on the dark web as a subscription-based RAT platform.
In Norse mythology, Loki, the god of mischief, has powerful and deceptive transformation abilities. True to its namesake, the malware LokiBot has appeared in numerous variants and payload formats since its discovery more than a decade ago. In this blog, we take a closer look at a multi-stage LokiBot sample from a recent campaign.
The Gentlemen is an active ransomware and extortion operation that emerged publicly in the second half of 2025 and rapidly scaled into a high-volume threat actor. Rather than a fully new group, it seems to be a continuation or reorganization of prior ransomware affiliate activity, with links to the Qilin ecosystem and the Russian-speaking actor “hastalamuerte". Its growth likely reflects existing ransomware experience, affiliate relationships, and access to resources.