Novel KarstoRAT RAT Enables Webcam Monitoring, Audio Recording, and Remote Payload Execution
ID: 8e899bde-3156-562e-99bd-565b0ee745c8
STIX ID: report--8e899bde-3156-562e-99bd-565b0ee745c8
Feed Name: cybersecurityNews.com
KarstoRAT is a newly identified 64-bit Windows remote access trojan observed in early 2026 that provides attackers with webcam capture, audio recording, keylogging, screenshots, and on-demand payload execution; the analyzed sample uses WinINet to communicate with a hardcoded C2 at 212.227.65.132 over port 15144, maintains a two-second heartbeat, and employs persistence via a Run key ("SecurityService"), a Scheduled Task ("SystemCheck"), Startup folder copy, and a fodhelper.exe UAC bypass. The adversary distributes the malware via socially engineered fake sites (a fake Roblox trading site and a game-cheat panel) and operates a layered C2 including SSH tunnels, Node.js APIs, VMess proxied through Cloudflare Argo with TLS fingerprinting; recommended actions include blocking the C2 IP and ports 15144/13614, scanning for the "SecurityNotifier" user agent, checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SecurityService and Scheduled Tasks named "SystemCheck", and flagging fodhelper.exe combined with HKCU registry changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
