logo

xRAT Malware Attacking Windows Users Disguised as Adult Game

ID: ed486473-d356-57c9-879d-89c293c91949

STIX ID: report--ed486473-d356-57c9-879d-89c293c91949

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Ahnlab/ASEC researchers identified a coordinated campaign in Korea distributing xRAT/QuasarRAT disguised as fake games on popular webhard file‑sharing sites; the malware installs via a ZIP containing Game.exe and Data*.Pak files, drops components (Play.exe, GoogleUpdate.exe, WinUpdate.db), decrypts and injects shellcode into explorer.exe, patches EtwEventWrite to disable Windows event logging, and performs system reconnaissance, keylogging, and unauthorized file transfers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.