#CabbageRAT

Malware/Tool

2026-04-14 • "Hello? I can’t hear you": Investigating UNC1069’s Fake Meeting Tactics

CabbageRAT, also called CageyChameleon, is a remote-access Trojan used in fake-meeting attacks against cryptocurrency and Web3 targets. Windows variants written in VBS collect host information, enumerate processes and Chrome extensions, exfiltrate data, and retrieve Base64-encoded, XOR-encrypted payloads for in-memory or on-disk execution. One variant persists through a shortcut in the Windows Startup folder. A related Linux ELF build uses HTTP POST, gathers system and network details, downloads and decrypts later stages, and executes them from a temporary directory. UNC1069 delivered these variants through ClickFix-style meeting prompts.

Tagged Reports

« Back