WebRAT malware spread via fake vulnerability exploits on GitHub
ID: 9db9a323-4ace-517d-afaa-cbc214e086ff
STIX ID: report--9db9a323-4ace-517d-afaa-cbc214e086ff
Feed Name: Bleeping Computer
Kaspersky researchers uncovered a campaign that distributes the WebRAT backdoor through GitHub repositories posing as proof-of-concept exploit code for recent CVEs; the delivered package uses a password-protected ZIP and dropper (rasmanesc.exe) to elevate privileges, disable Defender, and install an infostealer capable of stealing credentials, cryptocurrency wallets, and spying via webcam/screenshots. Fifteen malicious repositories were removed, but the report warns developers and researchers to test untrusted exploit code only in isolated environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
