Pulsar RAT: Multi-Stage Windows Malware Campaign Exploits Discord and Telegram

Pulsar RAT: Multi-Stage Windows Malware Campaign Exploits Discord and Telegram

First seen 10 Feb 2026, 22:20 UTC CsoonlineSocprime 78% similarity 32.9

Article Content

Browse articles
ThreatCluster

A multi-stage Windows malware campaign involving the Pulsar RAT has been reported, utilizing a concealed batch script, PowerShell loader, and Donut-generated shellcode for stealthy operations. The malware targets sensitive data through credential theft, webcam/audio capture, and clipboard monitoring, with exfiltration conducted via Discord webhooks and Telegram bots. Affected systems maintain persistence through various techniques, including scheduled tasks and Run key entries.

ThreatCluster AI

Timeline

2026-02-02
Point Wild discloses Pulsar RAT campaign
2026-02-03
Socprime reports on Donut shellcode and RAT
2026-02-09
Socprime details multi-stage malware chain

Community

Browse all →

Tracked Entities in This Story