Skip to content
Pulsar RAT: Multi-Stage Windows Malware Campaign Exploits Discord and Telegram

Pulsar RAT: Multi-Stage Windows Malware Campaign Exploits Discord and Telegram

First seen 10 Feb 2026, 22:20 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

A multi-stage Windows malware campaign involving the Pulsar RAT has been reported, utilizing a concealed batch script, PowerShell loader, and Donut-generated shellcode for stealthy operations. The malware targets sensitive data through credential theft, webcam/audio capture, and clipboard monitoring, with exfiltration conducted via Discord webhooks and Telegram bots. Affected systems maintain persistence through various techniques, including scheduled tasks and Run key entries.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2026-02-02
Point Wild discloses Pulsar RAT campaign
2026-02-03
Socprime reports on Donut shellcode and RAT
2026-02-09
Socprime details multi-stage malware chain

More articles in this cluster (3)

Following this threat?

Track Pulsar RAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed