WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users
ID: 90b60fc4-4263-5ada-b520-e8a31e2a82e1
STIX ID: report--90b60fc4-4263-5ada-b520-e8a31e2a82e1
Feed Name: cybersecurityNews.com
A newly observed WebRAT campaign leverages GitHub repositories, YouTube comments, and pirated software sites to distribute a stealer/RAT disguised as game cheats and utilities. The malware harvests credentials (Steam, Discord, Telegram, cryptocurrency wallets), provides desktop monitoring, webcam access, and full remote control, and can deploy secondary payloads (e.g., cryptocurrency miners). Solar analysts traced early versions to January 2025 and published IoCs; attackers use social engineering to maximize spread and the malware is available for purchase in criminal channels, creating notable risk to individual gamers and corporate environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
