logo

xRAT (QuasarRAT) Malware Being Distributed Through Adult Game Webhard

ID: fd00c718-4e41-56de-86c3-cfc1ae754e7c

STIX ID: report--fd00c718-4e41-56de-86c3-cfc1ae754e7c

Feed Name: ASEC

Threat Score
72/100

Date Published: 2026-01-04

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC discovered xRAT (QuasarRAT) being distributed through Korean webhard sites disguised as an adult game; the installer drops a launcher and Pak files that place Play.exe, GoogleUpdate.exe, and WinUpdate.db into user AppData, where GoogleUpdate.exe AES-decrypts shellcode from WinUpdate.db, injects xRAT into explorer.exe, and patches EtwEventWrite to disable ETW logging. The RAT performs system information collection, keylogging, and file transfer. The report includes MD5 IOCs and detections and warns users to avoid downloading executables from file-sharing sites and to obtain software from official sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.