logo

WrnRAT Distributed Under the Guise of Gambling Games

ID: 18bb7124-2223-514d-a475-76d286801be9

STIX ID: report--18bb7124-2223-514d-a475-76d286801be9

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-10-21

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC identified an active campaign distributing a Python-based RAT called “WrnRAT” disguised as gambling games and fake optimization software; .NET droppers deploy a launcher and install an executable masquerading as Internet Explorer (iexplorer.exe). WrnRAT (packaged with PyInstaller) captures user screenshots, sends basic system information, can terminate processes, and is paired with additional components that alter firewall settings. The report includes sample MD5 hashes, download URLs, and domain names; users are advised to avoid untrusted installers and update antivirus definitions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.