#webrat
Webrat sfrutta la blockchain TON per nascondersi: il malware che ruba account diventa più difficile da bloccare
#blockchain #computer #criptovalute #hacker #malware #sicurezza #steam #telegram #ton #virus #webrat
🔗 https://guruhitech.com/webrat-malware-blockchain-ton/
September 25, 2026 at 8:03 AM
Vírus por assinatura rouba dados e ainda faz piada de vítimas
A Kaspersky identificou o CrystalX RAT, malware como serviço em circulação desde janeiro de 2026. O produto é promovido no Telegram e em um canal dedicado no YouTube, com vídeos demonstrando funcionalidades num modelo de assinatura por níveis. A ferramenta oferece painel acessível e builder com bloqueio geográfico, anti-debugging e detecção de máquina virtual. O código é escrito em Go com semelhanças ao WebRAT, também chamado de Salat Stealer. As cargas são cifradas com ChaCha20 e compactadas com zlib. A comunicação com o C2 ocorre via WebSocket. Os módulos incluem acesso remoto por VNC, keylogger, captura de áudio e vídeo, e um clipper que substitui endereços de carteiras na área de transferência da vítima. O infostealer mira navegadores Chromium, Yandex e Opera, além de Steam, Discord e Telegram. O malware inclui prankware capaz de desativar dispositivos de entrada e exibir notificações falsas, funcionando como distração enquanto os módulos de coleta de dados operam em segundo plano.
www.tecmundo.com.br
April 2, 2026 at 8:42 PM
New CrystalX malware-as-a-service surfaced with remote access, data theft, keylogging, clipboard hijacking, and prankware features. Linked to WebRAT, it uses Go-based builder and encrypted payloads. #CrystalX #WebRAT #Russia
New CrystalRAT malware adds RAT, stealer and prankware features
CrystalX is a new malware-as-a-service promoted on Telegram and YouTube that offers remote access, data theft, keylogging, clipboard hijacking, and a variety of prankware features. Kaspersky links CrystalX to WebRAT (Salat Stealer) and describes a Go-based builder, user-friendly control panel, zlib-compressed ChaCha20-encrypted payloads, WebSocket C2, browser and app infostealers, remote VNC control, audio/video capture, and real-time keylogging. #CrystalX #WebRAT
www.hendryadrian.com
April 2, 2026 at 5:40 AM
March 2026 reveals CrystalX, a versatile RAT combining spyware, stealer, keylogger, clipper, remote access, and prankware features. Distributed via Telegram and YouTube with multiple subscription tiers. #CrystalXRAT #MalwareTrends #Russia
A laughing RAT: CrystalX combines spyware, stealer, and prankware features
In March 2026 researchers uncovered an active MaaS campaign promoting CrystalX (initially marketed as Webcrystal/WebRAT) via private Telegram chats and a YouTube channel; the RAT offers a builder and a wide feature set including stealer, keylogger, clipper, remote access, spyware, and extensive prankware. Kaspersky detects it as Backdoor.Win64.CrystalX.*, Trojan.Win64.Agent.*, and Trojan.Win32.Agentb.gen, telemetry shows active development and dozens of victims so far. #CrystalXRAT #Webcrystal
www.hendryadrian.com
April 1, 2026 at 12:40 PM
🟢 Webrat malware masquerades as exploits and spreads via GitHub

🗨️ In spring 2025, security researchers discovered the Webrat trojan, which was being distributed under the guise of cheats…

#news
Webrat malware masquerades as exploits and spreads via GitHub
Read more
hackmag.com
March 30, 2026 at 8:00 AM
WebRAT Malware Spreads Through Fake GitHub Exploit Repositories #CyberAttacks #cybertheft #datasecurity
WebRAT Malware Spreads Through Fake GitHub Exploit Repositories
 The WebRAT malware is being distributed through GitHub repositories that falsely claim to host proof-of-concept exploits for recently disclosed security vulnerabilities. This marks a shift in the malware’s delivery strategy, as earlier campaigns relied on pirated software and cheats for popular games such as Roblox, Counter-Strike, and Rust. First identified at the beginning of the year, WebRAT operates as a backdoor that allows attackers to gain unauthorized access to infected systems and steal sensitive information, while also monitoring user activity.  A report published by cybersecurity firm Solar 4RAYS in May detailed the scope of WebRAT’s capabilities. According to the findings, the malware can harvest login credentials for platforms including Steam, Discord, and Telegram, along with extracting data from cryptocurrency wallets. Beyond credential theft, WebRAT poses a serious privacy threat by enabling attackers to activate webcams and capture screenshots, exposing victims to covert surveillance.  Since at least September, the threat actors behind WebRAT have expanded their tactics by creating GitHub repositories designed to appear legitimate. These repositories present themselves as exploit code for high-profile vulnerabilities that have received widespread media attention. Among the issues referenced are a Windows flaw that allows remote code execution, a critical authentication bypass in the OwnID Passwordless Login plugin for WordPress, and a Windows privilege escalation vulnerability that enables attackers to gain elevated system access. By exploiting public awareness of these vulnerabilities, the attackers increase the likelihood that developers and security researchers will trust and download the malicious files.  Security researchers at Kaspersky identified 15 GitHub repositories linked to the WebRAT campaign. Each repository contained detailed descriptions of the vulnerability, explanations of the supposed exploit behavior, and guidance on mitigation. Based on the structure and writing style of the content, Kaspersky assessed that much of the material was likely generated using artificial intelligence tools, adding to the appearance of legitimacy. The fake exploits are distributed as password-protected ZIP archives containing a mix of decoy and malicious components.  These include empty files, corrupted DLLs intended to mislead analysis, batch scripts that form part of the execution chain, and a dropper executable named rasmanesc.exe. Once launched, the dropper elevates system privileges, disables Windows Defender, and downloads the WebRAT payload from a hardcoded remote server, enabling full compromise of the system.   Kaspersky noted that the WebRAT variant used in this campaign does not introduce new features and closely resembles previously documented samples. Although all identified malicious repositories have been removed from GitHub, researchers warn that similar lures could resurface under different names or accounts.  Security experts continue to advise that exploit code from unverified sources should only be tested in isolated, controlled environments to reduce the risk of infection.
dlvr.it
January 9, 2026 at 4:18 PM
Notícia da BleepingComputer

"WebRAT malware spread via fake vulnerability exploits on GitHub" #bolhasec
WebRAT malware spread via fake vulnerability exploits on GitHub
The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities.
www.bleepingcomputer.com
January 8, 2026 at 11:30 PM
Dangerous WebRAT malware now being spread by GitHub repositories Security researchers find 15 malicious repositories Kaspersky finds 15 malicious GitH...#news https://www.techradar.com/pro/security/dangerous-webrat-malware-now-being-spread-by-github-repositories
January 8, 2026 at 7:27 PM
December 30, 2025 at 7:00 PM
🚩WebRAT Malware Abuses Fake GitHub Proof-of-Concept Exploits to Infect Developers and Security Researchers #WebRAT #malware is spreading via fake #GitHub exploit repos, targeting developers and ...

#TIGR #malware

Origin | Interest | Match
Awakari App
awakari.com
December 29, 2025 at 2:40 PM
GitHub now ships 0-day Trojans gift-wrapped as 9.8-CVSS exploits: click “Download ZIP,” unlock with filename, get pwned by your own curiosity.
Webrat, disguised as exploits, is spreading via GitHub repositories
We dissect the new Webrat campaign where the Trojan spreads via GitHub repositories, masquerading as critical vulnerability exploits to target cybersecurity researchers.
securelist.com
December 28, 2025 at 8:36 PM
WebRAT-Malware wird derzeit über gefälschte PoC-Exploits auf GitHub verteilt.
Kaspersky fand 15 betrügerische Repos (mutmaßlich KI-generiert), inzwischen gelöscht.
Die Downloads enthalten einen Dropper, der Rechte erhöht, Defender deaktiviert & WebRAT nachlädt.
Die Backdoor stiehlt Zugangsdaten […]
Original post on mastodon.social
mastodon.social
December 28, 2025 at 11:00 AM
📌 Webrat Malware: Evolving Tactics and Targeting Cybersecurity Beginners https://www.cyberhub.blog/article/17303-webrat-malware-evolving-tactics-and-targeting-cybersecurity-beginners
Webrat Malware: Evolving Tactics and Targeting Cybersecurity Beginners
In 2025, cybersecurity researchers identified the Webrat malware, initially distributed via GitHub as cheats for popular games such as Rust, Counter-Strike, and Roblox, as well as cracked versions of software. By September 2025, the operators of Webrat expanded their target demographic to include students and beginners in cybersecurity, concealing the malware within exploits for recent vulnerabilities. Notably, the source does not provide specific CVE identifiers or additional technical details about the vulnerabilities being exploited. The use of GitHub as a distribution vector is particularly concerning due to the platform's widespread use and trust among developers and cybersecurity professionals. This tactic leverages the credibility of GitHub to lure unsuspecting users into downloading malicious files. The shift in targeting from gamers to students and beginners in cybersecurity indicates an evolution in the attackers' strategy, aiming to exploit less experienced individuals who may be more susceptible to social engineering techniques. The impact of Webrat malware is primarily on users who are deceived by lures related to security tools or pirated content. The use of exploits for recent vulnerabilities suggests that the attackers are keeping abreast of the latest security flaws, which could pose significant risks to unpatched systems. However, the lack of specific CVE details makes it challenging to assess the exact nature of these exploits and their potential impact. From an expert perspective, this incident underscores the importance of verifying the source of code and files downloaded from the internet. Cybersecurity professionals should be aware of the evolving tactics employed by malware operators and ensure that their teams are educated about these threats. Organizations should prioritize patching systems against known vulnerabilities to mitigate the risk of exploitation. In conclusion, the Webrat malware campaign highlights the ongoing challenge of social engineering attacks and the need for continuous education and awareness in the cybersecurity community. The use of trusted platforms like GitHub for malware distribution serves as a reminder of the importance of vigilance and verification in cybersecurity practices.
www.cyberhub.blog
December 28, 2025 at 6:40 AM
Webrat turns GitHub PoCs into a malware trap www.csoonline.com/article/4111...
Webrat turns GitHub PoCs into a malware trap
The known RAT aimed at gamers is now targeting security professionals searching GitHub for PoCs and exploit codes.
www.csoonline.com
December 27, 2025 at 1:12 AM
Webrat Malware Targets Students and Junior Security Researchers Through Fake Exploits #AIcybersecurity #AItools #CyberSecurity
Webrat Malware Targets Students and Junior Security Researchers Through Fake Exploits
 In early 2025, security researchers uncovered a new malware family dubbed Webrat, which at that time was predominantly targeting ordinary users through fake distribution methods. The first propagation involved masking malware as cheats for online games-like Rust, Counter-Strike, and Roblox-but also as cracked versions of some commercial software. By the second half of that year, though, the Webrat operators had indeed widened their horizons, shifting toward a new target group that covered students and young professionals seeking careers in information security.  This evolution started to surface in September and October 2025, when researchers discovered a campaign spreading Webrat through open GitHub repositories. The attackers embedded the malicious payloads as proof-of-concept exploits of highly publicized software vulnerabilities. Those vulnerabilities were chosen due to their resonance in security advisories and high severity ratings, making the repositories look relevant and credible for people searching for hands-on learning materials.   Each of the GitHub repositories was crafted to closely resemble legitimate exploit releases. They all had detailed descriptions outlining the background of the vulnerability, affected systems, steps to install it, usage, and the most recommended ways of mitigation. Many of the repository descriptions have a similar or almost identical structure; the defensive advice offered is often strikingly similar, adding strong evidence that they were generated through automated or AI-assisted tools rather than various independent researchers. Inside each repository, users were instructed to fetch an archive with a password, labeled as the exploit package.  The password was hidden in the name of one of the files inside the archive, a move intended to lure users into unzipping the file and researching its contents. Once unpacked, the archive contains a set of files meant to masquerade or divert attention from the actual payload. Among those is a corrupted dynamic-link library file meant as a decoy, along with a batch file whose purpose was to instruct execution of the main malicious executable file. The main executable, when run, executed several high-risk actions: It tried to elevate its privileges to administrator level, disabled the inbuilt security protections such as Windows Defender, and then downloaded the Webrat backdoor from a remote server and started it. The Webrat backdoor provides a way to attackers for persistent access to infected systems, allowing them to conduct widespread surveillance and data theft activities. Webrat can steal credentials and other sensitive information from cryptocurrency wallets and applications like Telegram, Discord, and Steam. In addition to credential theft, it also supports spyware functionalities such as screen capture, keylogging, and audio and video surveillance via connected microphones and webcams. The functionality seen in this campaign is very similar to versions of Webrat described in previous incidents.  It seems that the move to dressing the malware up as vulnerability exploits represents an effort to affect hobbyists rather than professionals. Professional analysts normally analyze such untrusted code in a sandbox or isolated environment, where such attacks have limited consequences.  Consequently, researchers believe the attack focuses on students and beginners with lax operational security discipline. It ranges in topic from the risks in running unverified code downloaded from open-source sites to the need to perform malware analysis and exploit testing in a sandbox or virtual machine environment.  Security professionals and students are encouraged to be keen in their practices, to trust only known and reputable security tools, and to bypass protection mechanisms only when this is needed with a clear and well-justified reason.
dlvr.it
December 26, 2025 at 5:49 PM
December 26, 2025 at 5:00 PM
WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users:

potatosecuritynews.com/webrat-malwa...
December 26, 2025 at 9:29 AM
WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users:

cybersecuritynews.com/webrat-malwa...
December 26, 2025 at 9:28 AM
GitHub’da sahte güvenlik açığı exploitleri üzerinden yayılan WebRAT zararlı yazılımı Daha önce Roblox, Counter Strike ve Rust gibi oyunlar için korsan yazılımlar ve hileler yoluyla...

#security #github #technews #technology #cybersecurity

Origin | Interest | Match
Awakari App
awakari.com
December 26, 2025 at 7:20 AM
Feed: "GBHackers Security | #1 Globally Trusted Cyber Security News Platform"
By: Mayura Kathir on Wednesday, December 24, 2025
WebRAT Malware Campaign Leveraging GitHub-Hosted Proof-of-Concept Code
Cybersecurity specialists from the Solar 4RAYS cyberthreat research center, a division of the Solar Group, have uncovered a dangerous new malware strain dubbed "Webrat."
gbhackers.com
December 25, 2025 at 5:46 AM
GitHub Exploits Spread WebRAT: Devs Get Free Malware, Prague Still Checking Its Faxes
PANIC 68% | Lag 0.0h | Threat actors are leveraging fake vulnerability proof-of-concept exploits on GitHub. These repositor
#AfterShockIndex
https://index.deceiver.io/story/story:1766621642:9588
December 25, 2025 at 12:14 AM