logo

Microsoft warns of RAT delivered through trojanized gaming utilities

ID: 1129a662-8972-572d-9456-99afb56126b3

STIX ID: report--1129a662-8972-572d-9456-99afb56126b3

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-02-28

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Microsoft warns of a campaign that lures users into running trojanized gaming utilities distributed via browsers and chat platforms to deploy a stealthy multi-purpose RAT. The attackers used a malicious downloader that ran a portable Java runtime to execute a harmful JAR, leveraged PowerShell and LOLBins (cmstp.exe) for stealth, modified Microsoft Defender exclusions, and established persistence via scheduled tasks and startup scripts; the RAT connected to C2 79.110.49.15 and Microsoft published related IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.