Threat Advisory

xRAT Malware Exploiting Windows Users and Stealing Login Details

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A widespread malware distribution campaign has been observed in which a remote access Trojan (RAT), commonly referred to as xRAT or QuasarRAT, is being distributed under the guise of downloadable game files on popular file-sharing platforms. These files are hosted on webhard services that masquerade as legitimate entertainment downloads, including adult games, to trick users into executing the malicious content. This deceptive delivery method takes advantage of users trust in seemingly benign executable files and increases the likelihood of inadvertent infection.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A widespread malware distribution campaign has been observed in which a remote access Trojan (RAT), commonly referred to as xRAT or QuasarRAT, is being distributed under the guise of downloadable game files on popular file-sharing platforms. These files are hosted on webhard services that masquerade as legitimate entertainment downloads, including adult games, to trick users into executing the malicious content. This deceptive delivery method takes advantage of users trust in seemingly benign executable files and increases the likelihood of inadvertent infection.[emaillocker id="1283"]

In this scheme, attackers package the malware within compressed archives that mimic legitimate game downloads. Once extracted, the executable labelled as the game launcher actually initiates the malware deployment sequence. The fake launcher copies and renames companion files into a users local application data directory, disguising them with names resembling trusted system components. One of these files performs decryption and injects the xRAT payload into a widely trusted process, while also disabling event logging mechanisms to hinder detection. After successful injection, the backdoor performs a range of malicious actions including system information harvesting, keylogging, and unauthorized file transfers, enabling persistent access on compromised machines. Security detections flag multiple indicators related to the loader and its behavior, highlighting both shellcode execution and backdoor activity emerging from these webhard-origin downloads.

It highlights the continued risk posed by malware distribution through deceptive file-sharing sites and gamified lure content. Users should exercise extreme caution when downloading executables from unverified or informal sources, especially those offering entertainment software, and organizations should enforce strict endpoint security measures, including robust web filtering, application allow-listing, and user awareness training to mitigate infection vectors like this one.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial Access T1566.002 Phishing Spearphishing Link
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
T1106 Native API
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defense Evasion T1027.002 Obfuscated Files or Information Software Packing
T1055.012 Process Injection Process Hollowing
T1562.002 Impair Defenses Disable Windows Event Logging
Discovery T1082 System Information Discovery -
T1057 Process Discovery -
Collection T1113 Screen Capture -
Command and Control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

 

MBC MAPPING:

Objective Behavior ID Behavior
Anti-Behavioral Analysis B0001 Debugger Detection
Anti-Static Analysis B0012 Disassembler Evasion
B0032 Executable Code Obfuscation
Collection E1056 Input Capture
Command and Control B0030 C2 Communication
Defense Evasion F0001 Software Packing
F0004 Disable or Evade Security Tools
E1027 Obfuscated Files or Information
Execution E1059 Command and Scripting Interpreter
E1204 User Execution
Exfiltration E1020 Automated Exfiltration
Lateral Movement E1105 Ingress Tool Transfer
Persistence F0012 Registry Run Keys / Startup Folder
E1112 Modify Registry
Privilege Escalation E1055 Process Injection

 

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu