logo

New Python RAT Targets Gamers via Minecraft

ID: f934fc24-fa7b-5916-b2e9-68257281938f

STIX ID: report--f934fc24-fa7b-5916-b2e9-68257281938f

Feed Name: Netskope Threat Labs

Threat Score
65/100

Date Published: 2025-10-22

Date Updated: 2026-04-28

Author: Nikhil Hegde

...
...

Netskope analyzes a PyInstaller-built Python RAT masquerading as the "Nursultan Client" Minecraft tool that uses a hardcoded Telegram Bot token and allowed-user IDs for C2. The malware can steal Discord authentication tokens, collect system information, capture screenshots and webcam images, and open/display arbitrary URLs or images; it targets gamers, is likely distributed as Malware-as-a-Service, includes published IOCs, and exhibits flawed persistence and limited anti-analysis sophistication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.