Abyssos functions as a post-exploitation framework This article explores abyssos malware employs. . Once an attacker gains access to a device, they can utilize the Remote Access Tool (RAT) to explore files, gather credentials, monitor activities, execute commands, download additional payloads, and remotely interact with the victim system.

By employing commands like HVNC_START, they can initiate a hidden VNC session and run applications such as Chrome, Microsoft Edge, Firefox, Brave, Opera, Vivaldi, PowerShell, Command Prompt, File Explorer, and multiple email clients. If a user is already logged in to email, cloud storage, financial services, or enterprise portals, stolen cookies may enable attackers to access those accounts as the victim.

One module named GRABCOOKIES is likely used to gather browser cookies and send files from the temporary fontconfigs directory back to the command-and-control server. It also captures clipboard content, monitors system processes, records screens, collects system information, and maps active TCP and UDP connections. Attackers can exploit remote command shells, terminate processes, reboot systems, and execute User Account Control bypass commands through Abyssos.

The malware employs several techniques to thwart analysis. Deployed exclusively on authorized cybersecurity platforms like MISP, VirusTotal, or through your Security Information and Event Management (SIEM) system.