WrnRAT Distributed Under the Guise of Gambling Games
ID: 18bb7124-2223-514d-a475-76d286801be9
STIX ID: report--18bb7124-2223-514d-a475-76d286801be9
Feed Name: ASEC
AhnLab ASEC identified an active campaign distributing a Python-based RAT called “WrnRAT” disguised as gambling games and fake optimization software; .NET droppers deploy a launcher and install an executable masquerading as Internet Explorer (iexplorer.exe). WrnRAT (packaged with PyInstaller) captures user screenshots, sends basic system information, can terminate processes, and is paired with additional components that alter firewall settings. The report includes sample MD5 hashes, download URLs, and domain names; users are advised to avoid untrusted installers and update antivirus definitions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
