: Allows attackers to run shell commands or scripts on the host.

: Often uses Discord Webhooks as a Command and Control (C2) channel to exfiltrate data. 🛡️ Detection and Mitigation

: If you find RPS420.7z , do not extract it; the internal .exe is usually flagged by VirusTotal.

: Watch for unusual outbound traffic to Discord API endpoints or unknown IP addresses.

: Targets browser data, including saved passwords, cookies, and autofill info.

: Captures live screenshots or video streams of the victim’s desktop.

Related products

Back to overview