logo

xRAT Malware Targets Windows Users via Fake Adult Game

ID: 13f0f856-8d72-5027-9b25-33c553d0b821

STIX ID: report--13f0f856-8d72-5027-9b25-33c553d0b821

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**AhnLab ASEC reports an active distribution campaign using Korean webhard services to spread xRAT/QuasarRAT disguised as adult game ZIPs; a malicious launcher extracts components (renamed to Play.exe, GoogleUpdate.exe, WinUpdate.db), decrypts and injects shellcode into explorer.exe, disables Event Tracing for Windows (ETW), and enables credential theft and remote access.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.