OctoRAT is a malware family tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed December 4, 2025; most recent activity December 4, 2025.
OctoRAT is a malware family that is delivered as the final payload after infection via a malicious Visual Studio Code extension, typically deployed alongside Anivia Loader. It functions as a remote access trojan (RAT) enabling attacker control over compromised hosts, highlighting a notable supply-chain/vector risk through developer tooling. This delivery method underscores the significance of VSCode extensions as an attack surface in cybersecurity.
A malicious Visual Studio Code (VSCode) extension has been identified as a vector for deploying the Anivia Loader and OctoRAT malware. This threat primarily affects users of the VSCode platform, enabling attackers to…