logo

Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms

ID: 46e01f71-94eb-5e20-bb2c-8431a5622d1d

STIX ID: report--46e01f71-94eb-5e20-bb2c-8431a5622d1d

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-02-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Threat actors are distributing trojanized gaming utilities via browsers and chat platforms to install multi-purpose RATs (e.g., Steaelite, DesckVB, KazakRAT). The attacks employ staged Java runtimes, PowerShell, and living-off-the-land binaries (cmstp.exe) for stealth, configure Microsoft Defender exclusions, maintain persistence via scheduled tasks and a startup script (world.vbs), and connect to C2 infrastructure (notably 79.110.49.15) to enable remote control, data exfiltration, and ransomware deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.