xRAT Malware Targets Windows Users via Fake Adult Game
ID: 13f0f856-8d72-5027-9b25-33c553d0b821
STIX ID: report--13f0f856-8d72-5027-9b25-33c553d0b821
Feed Name: GBHackers
Threat Score
**AhnLab ASEC reports an active distribution campaign using Korean webhard services to spread xRAT/QuasarRAT disguised as adult game ZIPs; a malicious launcher extracts components (renamed to Play.exe, GoogleUpdate.exe, WinUpdate.db), decrypts and injects shellcode into explorer.exe, disables Event Tracing for Windows (ETW), and enables credential theft and remote access.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
