EXECUTIVE SUMMARY:
A widespread malware distribution campaign has been observed in which a remote access Trojan (RAT), commonly referred to as xRAT or QuasarRAT, is being distributed under the guise of downloadable game files on popular file-sharing platforms. These files are hosted on webhard services that masquerade as legitimate entertainment downloads, including adult games, to trick users into executing the malicious content. This deceptive delivery method takes advantage of users trust in seemingly benign executable files and increases the likelihood of inadvertent infection.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A widespread malware distribution campaign has been observed in which a remote access Trojan (RAT), commonly referred to as xRAT or QuasarRAT, is being distributed under the guise of downloadable game files on popular file-sharing platforms. These files are hosted on webhard services that masquerade as legitimate entertainment downloads, including adult games, to trick users into executing the malicious content. This deceptive delivery method takes advantage of users trust in seemingly benign executable files and increases the likelihood of inadvertent infection.[emaillocker id="1283"]
In this scheme, attackers package the malware within compressed archives that mimic legitimate game downloads. Once extracted, the executable labelled as the game launcher actually initiates the malware deployment sequence. The fake launcher copies and renames companion files into a users local application data directory, disguising them with names resembling trusted system components. One of these files performs decryption and injects the xRAT payload into a widely trusted process, while also disabling event logging mechanisms to hinder detection. After successful injection, the backdoor performs a range of malicious actions including system information harvesting, keylogging, and unauthorized file transfers, enabling persistent access on compromised machines. Security detections flag multiple indicators related to the loader and its behavior, highlighting both shellcode execution and backdoor activity emerging from these webhard-origin downloads.
It highlights the continued risk posed by malware distribution through deceptive file-sharing sites and gamified lure content. Users should exercise extreme caution when downloading executables from unverified or informal sources, especially those offering entertainment software, and organizations should enforce strict endpoint security measures, including robust web filtering, application allow-listing, and user awareness training to mitigate infection vectors like this one.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial Access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.003 | Command and Scripting Interpreter | Windows Command Shell |
| T1106 | Native API | ||
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defense Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| T1055.012 | Process Injection | Process Hollowing | |
| T1562.002 | Impair Defenses | Disable Windows Event Logging | |
| Discovery | T1082 | System Information Discovery | - |
| T1057 | Process Discovery | - | |
| Collection | T1113 | Screen Capture | - |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
MBC MAPPING:
| Objective | Behavior ID | Behavior |
| Anti-Behavioral Analysis | B0001 | Debugger Detection |
| Anti-Static Analysis | B0012 | Disassembler Evasion |
| B0032 | Executable Code Obfuscation | |
| Collection | E1056 | Input Capture |
| Command and Control | B0030 | C2 Communication |
| Defense Evasion | F0001 | Software Packing |
| F0004 | Disable or Evade Security Tools | |
| E1027 | Obfuscated Files or Information | |
| Execution | E1059 | Command and Scripting Interpreter |
| E1204 | User Execution | |
| Exfiltration | E1020 | Automated Exfiltration |
| Lateral Movement | E1105 | Ingress Tool Transfer |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| E1112 | Modify Registry | |
| Privilege Escalation | E1055 | Process Injection |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]