#WebRAT
Webrat sfrutta la blockchain TON per nascondersi: il malware che ruba account diventa più difficile da bloccare
#blockchain #computer #criptovalute #hacker #malware #sicurezza #steam #telegram #ton #virus #webrat
🔗 https://guruhitech.com/webrat-malware-blockchain-ton/
September 25, 2026 at 8:03 AM
The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities.
WebRAT malware spread via fake vulnerability exploits on GitHub
The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities.
www.bleepingcomputer.com
December 23, 2025 at 7:32 PM
had fun reading my "bluesky roast" - blueskyroast.com/roast/webrat... Found via @ngerakines.me. Hilarious.
Welcome to Todd-tropolis: Where Programming Meets Pork!
Todd blends engineering prowess with barbecue finesse in a delightful online fusion.
blueskyroast.com
December 2, 2024 at 9:01 PM
WebRAT malware spread via fake vulnerability exploits on GitHub
WebRAT malware spread via fake vulnerability exploits on GitHub
www.bleepingcomputer.com
December 24, 2025 at 9:49 AM
WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users
WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users
cybersecuritynews.com
December 24, 2025 at 8:43 AM
Webrat turns GitHub PoCs into a malware trap www.csoonline.com/article/4111...
Webrat turns GitHub PoCs into a malware trap
The known RAT aimed at gamers is now targeting security professionals searching GitHub for PoCs and exploit codes.
www.csoonline.com
December 27, 2025 at 1:12 AM
WebRAT-Malware wird derzeit über gefälschte PoC-Exploits auf GitHub verteilt.
Kaspersky fand 15 betrügerische Repos (mutmaßlich KI-generiert), inzwischen gelöscht.
Die Downloads enthalten einen Dropper, der Rechte erhöht, Defender deaktiviert & WebRAT nachlädt.
Die Backdoor stiehlt Zugangsdaten […]
Original post on mastodon.social
mastodon.social
December 28, 2025 at 11:00 AM
Kaspersky researchers have uncovered a stealthy campaign in which the Webrat Trojan, known for months to hide inside game cheats and cracked software, is now posing as proof-of-concept exploit repositories on GitHub. www.csoonline.com/article/4111...
Webrat turns GitHub PoCs into a malware trap
The known RAT aimed at gamers is now targeting security professionals searching GitHub for PoCs and exploit codes.
www.csoonline.com
December 24, 2025 at 1:12 PM
Notícia da BleepingComputer

"WebRAT malware spread via fake vulnerability exploits on GitHub" #bolhasec
WebRAT malware spread via fake vulnerability exploits on GitHub
The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities.
www.bleepingcomputer.com
January 8, 2026 at 11:30 PM
Vírus por assinatura rouba dados e ainda faz piada de vítimas
A Kaspersky identificou o CrystalX RAT, malware como serviço em circulação desde janeiro de 2026. O produto é promovido no Telegram e em um canal dedicado no YouTube, com vídeos demonstrando funcionalidades num modelo de assinatura por níveis. A ferramenta oferece painel acessível e builder com bloqueio geográfico, anti-debugging e detecção de máquina virtual. O código é escrito em Go com semelhanças ao WebRAT, também chamado de Salat Stealer. As cargas são cifradas com ChaCha20 e compactadas com zlib. A comunicação com o C2 ocorre via WebSocket. Os módulos incluem acesso remoto por VNC, keylogger, captura de áudio e vídeo, e um clipper que substitui endereços de carteiras na área de transferência da vítima. O infostealer mira navegadores Chromium, Yandex e Opera, além de Steam, Discord e Telegram. O malware inclui prankware capaz de desativar dispositivos de entrada e exibir notificações falsas, funcionando como distração enquanto os módulos de coleta de dados operam em segundo plano.
www.tecmundo.com.br
April 2, 2026 at 8:42 PM
WebRAT malware spread via fake vulnerability exploits on GitHub

The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities. Previously spread through pirated software and cheats for games like Roblox,…
WebRAT malware spread via fake vulnerability exploits on GitHub
The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities. Previously spread through pirated software and cheats for games like Roblox, Counter Strike, and Rust, WebRAT is a backdoor with info-stealing capabilities that emerged at the beginning of the year. According to a report from Solar 4RAYS in May, WebRAT can steal credentials for Steam, Discord, and Telegram accounts, as well as cryptocurrency wallet data.
nexttech-news.com
December 23, 2025 at 10:02 PM
📰 Judul: WebRAT Sebar Malware Lewat Eksploit Palsu di GitHub, Targetkan Peneliti dan Pengembang

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2025/12/24/webrat-malware-github-eksploit-palsu/

#cyb
er#cybersecurityu#githubs#infostealera#malwarel#supply-attack #webra#webrat
December 24, 2025 at 7:23 AM
ロシアのサイバーセキュリティ企業F6が、ハッキンググループNyashTeamのネットワークを特定・解体した。NyashTeamはDCRatやWebRat等のマルウェアを安価で提供していた。F6は110以上のドメイン、関連Telegramチャンネル、動画の削除を要請。 therecord.media/russia-hacke...
Russian-speaking hacker group disrupted by local researchers
Russian cybersecurity researchers identified and dismantled a network of domains operated by the hacker group NyashTeam.
therecord.media
July 22, 2025 at 9:28 PM
Webrat: quando la voglia di imparare sicurezza informatica diventa un vettore d’attacco

📌 Link all'articolo : www.redhotcyber.com/post/web...

#redhotcyber #news #cybersecurity #hacking #malware #minacceinformatiche #sicurezzainformatica
December 24, 2025 at 2:52 PM
WebRAT Malware Spreads Through Fake GitHub Exploit Repositories #CyberAttacks #cybertheft #datasecurity
WebRAT Malware Spreads Through Fake GitHub Exploit Repositories
 The WebRAT malware is being distributed through GitHub repositories that falsely claim to host proof-of-concept exploits for recently disclosed security vulnerabilities. This marks a shift in the malware’s delivery strategy, as earlier campaigns relied on pirated software and cheats for popular games such as Roblox, Counter-Strike, and Rust. First identified at the beginning of the year, WebRAT operates as a backdoor that allows attackers to gain unauthorized access to infected systems and steal sensitive information, while also monitoring user activity.  A report published by cybersecurity firm Solar 4RAYS in May detailed the scope of WebRAT’s capabilities. According to the findings, the malware can harvest login credentials for platforms including Steam, Discord, and Telegram, along with extracting data from cryptocurrency wallets. Beyond credential theft, WebRAT poses a serious privacy threat by enabling attackers to activate webcams and capture screenshots, exposing victims to covert surveillance.  Since at least September, the threat actors behind WebRAT have expanded their tactics by creating GitHub repositories designed to appear legitimate. These repositories present themselves as exploit code for high-profile vulnerabilities that have received widespread media attention. Among the issues referenced are a Windows flaw that allows remote code execution, a critical authentication bypass in the OwnID Passwordless Login plugin for WordPress, and a Windows privilege escalation vulnerability that enables attackers to gain elevated system access. By exploiting public awareness of these vulnerabilities, the attackers increase the likelihood that developers and security researchers will trust and download the malicious files.  Security researchers at Kaspersky identified 15 GitHub repositories linked to the WebRAT campaign. Each repository contained detailed descriptions of the vulnerability, explanations of the supposed exploit behavior, and guidance on mitigation. Based on the structure and writing style of the content, Kaspersky assessed that much of the material was likely generated using artificial intelligence tools, adding to the appearance of legitimacy. The fake exploits are distributed as password-protected ZIP archives containing a mix of decoy and malicious components.  These include empty files, corrupted DLLs intended to mislead analysis, batch scripts that form part of the execution chain, and a dropper executable named rasmanesc.exe. Once launched, the dropper elevates system privileges, disables Windows Defender, and downloads the WebRAT payload from a hardcoded remote server, enabling full compromise of the system.   Kaspersky noted that the WebRAT variant used in this campaign does not introduce new features and closely resembles previously documented samples. Although all identified malicious repositories have been removed from GitHub, researchers warn that similar lures could resurface under different names or accounts.  Security experts continue to advise that exploit code from unverified sources should only be tested in isolated, controlled environments to reduce the risk of infection.
dlvr.it
January 9, 2026 at 4:18 PM
Webrat Malware Targets Students and Junior Security Researchers Through Fake Exploits #AIcybersecurity #AItools #CyberSecurity
Webrat Malware Targets Students and Junior Security Researchers Through Fake Exploits
 In early 2025, security researchers uncovered a new malware family dubbed Webrat, which at that time was predominantly targeting ordinary users through fake distribution methods. The first propagation involved masking malware as cheats for online games-like Rust, Counter-Strike, and Roblox-but also as cracked versions of some commercial software. By the second half of that year, though, the Webrat operators had indeed widened their horizons, shifting toward a new target group that covered students and young professionals seeking careers in information security.  This evolution started to surface in September and October 2025, when researchers discovered a campaign spreading Webrat through open GitHub repositories. The attackers embedded the malicious payloads as proof-of-concept exploits of highly publicized software vulnerabilities. Those vulnerabilities were chosen due to their resonance in security advisories and high severity ratings, making the repositories look relevant and credible for people searching for hands-on learning materials.   Each of the GitHub repositories was crafted to closely resemble legitimate exploit releases. They all had detailed descriptions outlining the background of the vulnerability, affected systems, steps to install it, usage, and the most recommended ways of mitigation. Many of the repository descriptions have a similar or almost identical structure; the defensive advice offered is often strikingly similar, adding strong evidence that they were generated through automated or AI-assisted tools rather than various independent researchers. Inside each repository, users were instructed to fetch an archive with a password, labeled as the exploit package.  The password was hidden in the name of one of the files inside the archive, a move intended to lure users into unzipping the file and researching its contents. Once unpacked, the archive contains a set of files meant to masquerade or divert attention from the actual payload. Among those is a corrupted dynamic-link library file meant as a decoy, along with a batch file whose purpose was to instruct execution of the main malicious executable file. The main executable, when run, executed several high-risk actions: It tried to elevate its privileges to administrator level, disabled the inbuilt security protections such as Windows Defender, and then downloaded the Webrat backdoor from a remote server and started it. The Webrat backdoor provides a way to attackers for persistent access to infected systems, allowing them to conduct widespread surveillance and data theft activities. Webrat can steal credentials and other sensitive information from cryptocurrency wallets and applications like Telegram, Discord, and Steam. In addition to credential theft, it also supports spyware functionalities such as screen capture, keylogging, and audio and video surveillance via connected microphones and webcams. The functionality seen in this campaign is very similar to versions of Webrat described in previous incidents.  It seems that the move to dressing the malware up as vulnerability exploits represents an effort to affect hobbyists rather than professionals. Professional analysts normally analyze such untrusted code in a sandbox or isolated environment, where such attacks have limited consequences.  Consequently, researchers believe the attack focuses on students and beginners with lax operational security discipline. It ranges in topic from the risks in running unverified code downloaded from open-source sites to the need to perform malware analysis and exploit testing in a sandbox or virtual machine environment.  Security professionals and students are encouraged to be keen in their practices, to trust only known and reputable security tools, and to bypass protection mechanisms only when this is needed with a clear and well-justified reason.
dlvr.it
December 26, 2025 at 5:49 PM
New CrystalX malware-as-a-service surfaced with remote access, data theft, keylogging, clipboard hijacking, and prankware features. Linked to WebRAT, it uses Go-based builder and encrypted payloads. #CrystalX #WebRAT #Russia
New CrystalRAT malware adds RAT, stealer and prankware features
CrystalX is a new malware-as-a-service promoted on Telegram and YouTube that offers remote access, data theft, keylogging, clipboard hijacking, and a variety of prankware features. Kaspersky links CrystalX to WebRAT (Salat Stealer) and describes a Go-based builder, user-friendly control panel, zlib-compressed ChaCha20-encrypted payloads, WebSocket C2, browser and app infostealers, remote VNC control, audio/video capture, and real-time keylogging. #CrystalX #WebRAT
www.hendryadrian.com
April 2, 2026 at 5:40 AM
March 2026 reveals CrystalX, a versatile RAT combining spyware, stealer, keylogger, clipper, remote access, and prankware features. Distributed via Telegram and YouTube with multiple subscription tiers. #CrystalXRAT #MalwareTrends #Russia
A laughing RAT: CrystalX combines spyware, stealer, and prankware features
In March 2026 researchers uncovered an active MaaS campaign promoting CrystalX (initially marketed as Webcrystal/WebRAT) via private Telegram chats and a YouTube channel; the RAT offers a builder and a wide feature set including stealer, keylogger, clipper, remote access, spyware, and extensive prankware. Kaspersky detects it as Backdoor.Win64.CrystalX.*, Trojan.Win64.Agent.*, and Trojan.Win32.Agentb.gen, telemetry shows active development and dozens of victims so far. #CrystalXRAT #Webcrystal
www.hendryadrian.com
April 1, 2026 at 12:40 PM
“Webrat” Trap: Hackers Lure Junior Security Researchers with Fake GitHub Exploits
"Webrat" Trap: Hackers Lure Junior Security Researchers with Fake GitHub Exploits
Kaspersky warns of Webrat malware targeting researchers via fake GitHub PoCs for CVE-2025-10294 and other high-CVSS flaws to install a backdoor.
securityonline.info
December 24, 2025 at 3:43 AM
WebRAT malware spread via fake vulnerability exploits on GitHub
WebRAT malware spread via fake vulnerability exploits on GitHub
The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities.
www.bleepingcomputer.com
December 23, 2025 at 7:58 PM
WebRAT malware spread via fake vulnerability exploits on GitHub

The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities. Previously spread through pirated software and cheats for games like Roblox,…
WebRAT malware spread via fake vulnerability exploits on GitHub
The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities. Previously spread through pirated software and cheats for games like Roblox, Counter Strike, and Rust, WebRAT is a backdoor with info-stealing capabilities that emerged at the beginning of the year. According to a report from Solar 4RAYS in May, WebRAT can steal credentials for Steam, Discord, and Telegram accounts, as well as cryptocurrency wallet data.
nexttech-news.com
December 23, 2025 at 10:02 PM
#TechRadar Dangerous WebRAT malware now being spread by GitHub repositories https://techrad.ar/9KYw #Security #Pro
December 24, 2025 at 10:37 AM
December 30, 2025 at 7:00 PM
December 26, 2025 at 5:00 PM