xRAT Malware Attacking Windows Users Disguised as Adult Game
ID: ed486473-d356-57c9-879d-89c293c91949
STIX ID: report--ed486473-d356-57c9-879d-89c293c91949
Feed Name: cybersecurityNews.com
Threat Score
Ahnlab/ASEC researchers identified a coordinated campaign in Korea distributing xRAT/QuasarRAT disguised as fake games on popular webhard file‑sharing sites; the malware installs via a ZIP containing Game.exe and Data*.Pak files, drops components (Play.exe, GoogleUpdate.exe, WinUpdate.db), decrypts and injects shellcode into explorer.exe, patches EtwEventWrite to disable Windows event logging, and performs system reconnaissance, keylogging, and unauthorized file transfers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
