logo

NiceRAT Malware Targets South Korean Users via Cracked Software

ID: e8652f4b-6114-5d49-9024-357baa8b2b4a

STIX ID: report--e8652f4b-6114-5d49-9024-357baa8b2b4a

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-17

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

The report details active campaigns targeting South Korean users that distribute NiceRAT—an open-source Python remote access trojan and stealer—often bundled with cracked software; NiceRAT uses Discord webhooks for command-and-control and is offered in free and premium (MaaS) forms, while related activity references NanoCore, Nitol/Amadey, and the Bondnet botnet leveraging FRP reverse proxies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.