Socprime
Pulsar RAT: Multi-Stage Windows Malware Campaign Exploits Discord and Telegram
First seen 10 Feb 2026, 22:20 UTC
•
•78% similarity
•32.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A multi-stage Windows malware campaign involving the Pulsar RAT has been reported, utilizing a concealed batch script, PowerShell loader, and Donut-generated shellcode for stealthy operations. The malware targets sensitive data through credential theft, webcam/audio capture, and clipboard monitoring, with exfiltration conducted via Discord webhooks and Telegram bots. Affected systems maintain persistence through various techniques, including scheduled tasks and Run key entries.
ThreatCluster AI
Timeline
2026-02-02
Point Wild discloses Pulsar RAT campaign
2026-02-03
Socprime reports on Donut shellcode and RAT
2026-02-09
Socprime details multi-stage malware chain