According to security firm FireEye, cybercriminals are now abandoning well-known malware like Zeus in favor of more sophisticated (but harder to handle) Remote Access Trojans, such as Xtreme RAT.
Remote Access Trojans (or RATS) are malicious tools that install themselves on systems without the victims' knowledge, and allow unauthorized users to gain control of compromised computers remotely.
“During our research, we found that the main activity of Xtreme RATwas related to spam campaigns that were primarily used to distribute variants of Zeus and other banking malware. This is surprising, as RATs require manual intervention, unlike banking Trojans that are automated,” said FireEye security expert, Nart Villeneuve.
Xtreme RAT has been freely available on underground markets since June 2010 and can be used for various purposes, such as accessing and interacting with compromised computers via remote shell, uploading and downloading files, accessing the registry, and manipulating processes and services.
Sophisticated variants of the RAT are also used to take screenshots, and record video and audio, via connected devices.
Finally, hackers can also customize Xtreme RAT, adding new features, as the software's source code has been leaked online.

