logo

WebRAT malware spread via fake vulnerability exploits on GitHub

ID: 9db9a323-4ace-517d-afaa-cbc214e086ff

STIX ID: report--9db9a323-4ace-517d-afaa-cbc214e086ff

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky researchers uncovered a campaign that distributes the WebRAT backdoor through GitHub repositories posing as proof-of-concept exploit code for recent CVEs; the delivered package uses a password-protected ZIP and dropper (rasmanesc.exe) to elevate privileges, disable Defender, and install an infostealer capable of stealing credentials, cryptocurrency wallets, and spying via webcam/screenshots. Fifteen malicious repositories were removed, but the report warns developers and researchers to test untrusted exploit code only in isolated environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.