DesckVB RAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
February 5, 2026
Last Seen
June 4, 2026

DesckVB RAT is a malware family tracked by ThreatCluster, appearing in 3 threat clusters built from 5 intelligence report mentions.

DesckVB RAT is a malware family tracked across 3 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed February 5, 2026; most recent activity June 4, 2026.

Related Threat Clusters

  • DesckVB RAT Campaign Exploits Google DoubleClick for Malspam Delivery

    In May 2026, a malspam campaign utilizing the Google DoubleClick domain was identified, delivering the DesckVB remote access trojan (RAT). The attack begins with an HTML email attachment that redirects users through…

    6 articles · Updated June 3, 2026
  • STX RAT Emerges as Advanced Threat in Finance Sector

    The STX RAT, a previously undocumented remote access trojan, was identified in late February 2026 targeting the finance sector. It employs sophisticated stealth tactics, including multi-stage scripts and encrypted…

    5 articles · Updated April 9, 2026
  • DesckVB RAT Version 2.9 Emerges with Advanced Infection Techniques

    The DesckVB RAT version 2.9 has been identified as a sophisticated Remote Access Trojan actively used in malware campaigns since early 2026. This modular threat, built on the .NET framework, features a multi-stage…

    2 articles · Updated February 5, 2026

Recent Intelligence Reports

  • New malspam campaign uses Google DoubleClick to deliver DesckVB RAT — Scworld · June 4, 2026
  • Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT — Huntress · June 3, 2026
  • DesckVB RAT Uses Obfuscated JavaScript and Fileless .NET Loader to Evade Detection — Cybersecuritynews · April 10, 2026
  • New DesckVB RAT with Multi-stage Infection Chain and Plugin — Cybersecuritynews · February 5, 2026
  • New DesckVB RAT Unveiled with Multi-Stage Infection Chain and Plugin — Gbhackers · February 5, 2026

Frequently asked questions

What is DesckVB RAT?

DesckVB RAT is a malware family tracked by ThreatCluster, appearing in 3 threat clusters built from 5 intelligence report mentions.

Is DesckVB RAT still active?

The most recent intelligence report mentioning DesckVB RAT on ThreatCluster is dated June 4, 2026. Activity was first observed February 5, 2026, giving a tracked span from then to June 4, 2026.

What is DesckVB RAT associated with?

Across ThreatCluster reporting, DesckVB RAT most frequently co-occurs with Data Breach, Malware, Phishing, Trojan, T1012 - Query Registry, among 12 tracked related entities.

What are the latest developments involving DesckVB RAT?

The most significant recent cluster is “DesckVB RAT Campaign Exploits Google DoubleClick for Malspam Delivery” (6 articles · Updated June 3, 2026). DesckVB RAT appears across 3 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on DesckVB RAT?

DesckVB RAT appears in 5 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown