Netskope Threat Labs

Vatet

ATP Sandbox Adv. Heuristics

Vatet is a loader that researchers have documented alongside the PyXie remote access tool, delivering it to victims through fake software installers. It runs malicious code in memory and gives operators a foothold for credential theft and further payload deployment.

First seen
March 2022
Last seen
September 2026
Alert Name
Win32.Trojan.Vatet