This release consists of the following:
- MythicAgents Poseidon, reported to be in use by APT36
- Extract components from Rar archives exploiting CVE-2025-8088 path traversal vulnerability, including:
- SnipBot loader/downloader variant
- Rar + SnipBot: 391325100384964325ed4ace788c8bc2
- WinRunApp Downloader (CT named malware)
- Rar + WinRunApp: 6b4d7a63aa2a8b2a5a3fbad6c8e6533e
- SnipBot loader/downloader variant
- Ande Launcher (PowerShell)
- Kitsune Rat, a DcRat variant
- INC Ransomware support for Linux and Rust-compiled binaries