WebRAT Malware Campaign Leveraging GitHub-Hosted Proof-of-Concept Code
Cybersecurity experts at Solar 4RAYS, a division of the Solar Group, have identified a new malware strain known as "Webrat."
Cybersecurity experts at Solar 4RAYS, a division of the Solar Group, have identified a new malware strain known as "Webrat."
Webrat is a multifunctional remote access tool (RAT) and information stealer, targeting users through deceptive social engineering campaigns on code repositories and video streaming platforms.
Solar 4RAYS reports that Webrat emerged in January 2025, initially appearing on dark web channels. The malware grants attackers extensive control over infected systems, allowing for the exfiltration of sensitive personal and financial data.
The malware's key features include desktop screen capture and webcam access, enabling real-time monitoring of user activities.
Webrat's distribution strategy focuses on the gaming community and users seeking software workarounds. It often masquerades as "cheats" for games such as Rust, Counter-Strike, and Roblox.
Solar 4RAYS reports that Webrat emerged in January 2025, initially appearing on dark web channels.
Additionally, Webrat exploits regional software restrictions by posing as a "patch" or utility to restore access to banned applications like Discord in certain regions, such as Russia. These malicious files are distributed through:
GitHub Repositories: Hosting malware disguised as open-source tools or proof-of-concept exploits. YouTube Comments: Video tutorials with links to malware in the comments section. Pirated Software Sites: Repositories for cracked software.
Once installed, Webrat acts as a powerful stealer, targeting login credentials for platforms like Steam, Telegram, and Discord, as well as cryptocurrency wallets.
The malware allows attackers to control the victim's User Interface (UI), facilitating the download of additional payloads such as crypto miners and security software blockers.
Beyond financial theft, the stolen data is reportedly being used for blackmail and "swatting," a harassment tactic involving fake police calls to dispatch emergency teams to a victim's location.
Webrat poses a significant risk to corporate environments, as employees downloading unauthorized software may introduce the malware into enterprise networks, compromising sensitive data.
Solar 4RAYS advises using advanced antivirus solutions and avoiding downloads from untrusted sources or comment links to mitigate these risks.
Based on reporting by GBHackers.
