Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms
ID: 46e01f71-94eb-5e20-bb2c-8431a5622d1d
STIX ID: report--46e01f71-94eb-5e20-bb2c-8431a5622d1d
Feed Name: The Hacker News
Threat actors are distributing trojanized gaming utilities via browsers and chat platforms to install multi-purpose RATs (e.g., Steaelite, DesckVB, KazakRAT). The attacks employ staged Java runtimes, PowerShell, and living-off-the-land binaries (cmstp.exe) for stealth, configure Microsoft Defender exclusions, maintain persistence via scheduled tasks and a startup script (world.vbs), and connect to C2 infrastructure (notably 79.110.49.15) to enable remote control, data exfiltration, and ransomware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
