ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Rising Threat: Malware ‘Meal Kits’ Fuel Surge in Remote Access Trojan Campaigns

Kyle by Kyle
November 1, 2023
in Malware
Reading Time: 3 mins read
Meal Kits Casuing Spike in Remote administartive tool infections RATs
Share on FacebookShare on Twitter

The increase of affordable malware “meal kits,” priced at less than $100, is driving a surge in remote access Trojan (RAT) campaigns, frequently concealed within seemingly legitimate Excel and PowerPoint attachments in emails. HP Wolf Security has unveiled its “Q3 2023 Threat Insights Report,” which highlights a substantial increase in Excel files containing DLLs infected with the Parallax RAT. These files masquerade as authentic invoices, but when opened, they trigger the malware, as explained by HP’s senior malware analyst, Alex Holland. The Parallax RAT malware kits are readily available for $65 per month on underground hacking forums.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

HP’s report also reveals cybercriminals targeting prospective attackers with malware kits like XWorm, which are hosted in apparently legitimate repositories, such as GitHub. Furthermore, new RATs, including DiscordRAT 2.0, have recently emerged, according to researchers.

Remarkably, a significant 80% of the observed threats during the quarter originated from email-based attacks. Intriguingly, some proficient cybercriminals are now turning their attention to novices within RAT campaigns.

The Rise of Parallax

The HP report highlights that the Parallax RAT has catapulted from the 46th most favored payload in the second quarter of 2023 to the seventh spot in the subsequent quarter. According to Holland, this represents a substantial upswing in attackers exploiting this file format for malware distribution.

In one instance, researchers detected a Parallax RAT campaign employing a “Jekyll and Hyde” tactic, where two concurrent threads execute when a user opens a scanned invoice template. One thread opens the file as expected, while the other clandestinely runs malware in the background, rendering it challenging for users to discern an ongoing attack, as described in the report.

Notably, Parallax RAT had previously been linked to various malware campaigns at the outset of the pandemic, as detailed in a March 2020 blog post by Arnold Osipov, a malware researcher at Morphisec. Osipov affirmed its capabilities to bypass advanced detection solutions, steal credentials, and execute remote commands.

Osipov, speaking to Dark Reading, acknowledged that he had not witnessed the specific surge in Parallax attacks reported by HP. Nevertheless, he noted that RATs, in general, have posed an increasing threat in 2023.

RATs on the Rampage

Multiple spikes in RAT activity include an incident in July when Check Point Research highlighted a rise in Microsoft Office files harboring the Remcos RAT, first identified in 2016. Many of these malicious files were discovered on counterfeit websites crafted by threat actors.

Another RAT-based campaign gaining momentum is Houdini, which conceals Vjw0rm JavaScript malware. Houdini is a decade-old VBScript-based RAT that is now readily obtainable on hacking forums, exploiting OS-based scripting features.

It’s crucial to note that threats stemming from Houdini and Parallax may dwindle with Microsoft’s plan to deprecate VBScript. Microsoft recently announced that VBScript will only be accessible in future Windows releases upon request and will eventually be phased out. However, Holland cautioned that while this is favorable news for defenders, attackers will adapt and turn their attention to alternative methods.

Holland anticipates a shift towards formats that will remain supported on Windows, such as PowerShell and Bash, and also expects attackers to focus on innovative obfuscation techniques to circumvent endpoint security using these coding languages in the future.

Tags: Meal Kits
Previous Post

Unprecedented Cyber Breach via MOVEit Software Rattles Multiple Sectors

Next Post

Critical Security Flaw in Citrix Exposes Sensitive Data, Exploited by Threat Actors, Reveals Mandiant Report

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.