OctoRAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 4, 2025
Last Seen
December 4, 2025

OctoRAT is a malware family tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed December 4, 2025; most recent activity December 4, 2025.

Overview

OctoRAT is a malware family that is delivered as the final payload after infection via a malicious Visual Studio Code extension, typically deployed alongside Anivia Loader. It functions as a remote access trojan (RAT) enabling attacker control over compromised hosts, highlighting a notable supply-chain/vector risk through developer tooling. This delivery method underscores the significance of VSCode extensions as an attack surface in cybersecurity.

Related Threat Clusters

  • Malicious VSCode Extension Distributes Anivia Loader and OctoRAT

    A malicious Visual Studio Code (VSCode) extension has been identified as a vector for deploying the Anivia Loader and OctoRAT malware. This threat primarily affects users of the VSCode platform, enabling attackers to…

    2 articles · Updated December 4, 2025

Recent Intelligence Reports

  • Malicious VSCode Extension Deploys Anivia Loader and OctoRAT — Gbhackers · December 4, 2025
  • Threat Actors Using Malicious VSCode Extension to Deploy Anivia Loader and OctoRAT — Cybersecuritynews · December 4, 2025

CVSS v3.1 Breakdown