← Back to Feed

CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

August 10, 2026 · LevelBlue SpiderLabs · Severity: MEDIUM

LevelBlue SpiderLabs investigated a case where a loader chain led to an undocumented remote access trojan (RAT) named CNCMachineRMS. The analysis traces the infection process and reveals the unexpected final payload.

This post is the result of an investigation into a case we worked on, in which we traced a loader chain that ended where we didn't expect.

Key Takeaways

  • LevelBlue SpiderLabs traced a loader chain that ended with an undocumented RAT.
  • The RAT is named CNCMachineRMS and was discovered at the end of a BabaDeda chain.
  • The investigation reveals unexpected findings about the final payload in the loader chain.
☕ Buy a Coffee