blog.cyble.com New Borat RAT Combines Ransomware and DDoS Capabilities
Article Content
- •Borat RAT combines traditional RAT features with ransomware and DDoS capabilities.
- •The Trojan can disable security software and steal sensitive user data.
- •Cyble recommends enhanced security practices to mitigate risks from Borat.
A new Remote Access Trojan (RAT) named Borat has been identified, allowing attackers to control compromised systems and launch ransomware and DDoS attacks. Developed by an unknown creator, Borat can disable security features, record keystrokes, and steal sensitive data. It also includes a dashboard for executing DDoS attacks and deploying ransomware payloads. Cyble, the firm that reported on Borat, warns that this RAT represents a significant threat due to its multi-faceted capabilities. Organizations and individuals are advised to enhance their security measures to protect against this emerging threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Borat in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What capabilities does Borat RAT have?
Who is affected by Borat RAT?
What should organizations do to protect against Borat RAT?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…