xRAT Malware Targets Windows Users via Fake Adult Game
AhnLab Security Intelligence Center (ASEC) has identified a distribution campaign targeting Windows users through Korean web hard services. This campaign involves the xRAT (QuasarRAT) malware, which is disguised as legitimate adult game content to…
AhnLab Security Intelligence Center (ASEC) has identified a distribution campaign targeting Windows users through Korean web hard services. This campaign involves the xRAT (QuasarRAT) malware, which is disguised as legitimate adult game content to deceive users into downloading and executing harmful files.
Threat actors exploit the popularity of Korean web hard services for malware distribution. The xRAT campaign follows a pattern observed in previous campaigns, including njRAT, Remcos, UDP Rat, Korat, and XWorm malware. By disguising malicious payloads as legitimate software, games, and adult content, threat actors achieve high infection rates while evading initial detection.
The attack initiates when users download an adult game from a compromised web hard post. The ZIP file contains files such as "Game.exe," "Data1.Pak," "Data2.Pak," and "Data3.Pak." Users executing "Game.exe" unknowingly activate a malicious launcher. This launcher executes the real game launcher from "Data1.Pak," creating a semblance of legitimacy.
While the game operates, the malware is silently deployed in the background. Upon clicking the "Game Play!" button, the malware's infection chain begins. It copies files to hidden directories: "Data1.Pak" becomes "Play.exe" in the "Locales_module" folder, and "Data2.Pak" and "Data3.Pak" relocate to "C:\Users[User Account Name]\AppData\Local\Microsoft\Windows\Explorer" as "GoogleUpdate.exe" and "WinUpdate.db," respectively.
AhnLab Security Intelligence Center (ASEC) has identified a distribution campaign targeting Windows users through Korean web hard services.
"GoogleUpdate.exe" performs critical operations, decrypting "WinUpdate.db" using AES-based decryption to extract the final shellcode payload. It patches the EtwEventWrite() function in explorer.exe with a 0xC3 (RET) instruction, disabling Event Tracing for Windows (ETW) event logging.
The final payload injected into explorer.exe is xRAT, also known as QuasarRAT, an open-source remote access trojan with extensive capabilities. Once activated, xRAT can collect system information, perform keystroke logging, and download or upload files on the compromised system. These capabilities pose significant threats to both individual users and organizational security.
To mitigate risks, users should only download software from official vendor sites. Security teams are advised to implement endpoint detection and response (EDR) solutions and maintain updated systems with the latest security patches. AhnLab provides detection signatures, including File Detection for Data/Bin.Shellcode, Trojan/Win.Agent.C5834849, Trojan/Win.Loader.C5834845, and Trojan/Win32.Subti.C1663822, as well as Behavior Detection for Malware/MDP.Behavior.M1839.
The persistence of web hard-based malware distribution highlights the need for user awareness and strict software sourcing practices in combating cyber threats.
Based on reporting by GBHackers.
