logo

WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users

ID: 90b60fc4-4263-5ada-b520-e8a31e2a82e1

STIX ID: report--90b60fc4-4263-5ada-b520-e8a31e2a82e1

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-24

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A newly observed WebRAT campaign leverages GitHub repositories, YouTube comments, and pirated software sites to distribute a stealer/RAT disguised as game cheats and utilities. The malware harvests credentials (Steam, Discord, Telegram, cryptocurrency wallets), provides desktop monitoring, webcam access, and full remote control, and can deploy secondary payloads (e.g., cryptocurrency miners). Solar analysts traced early versions to January 2025 and published IoCs; attackers use social engineering to maximize spread and the malware is available for purchase in criminal channels, creating notable risk to individual gamers and corporate environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.