Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

xRAT Malware Targets Windows Users via Fake Adult Game

AhnLab Security Intelligence Center (ASEC) has identified a distribution campaign targeting Windows users through Korean web hard services. This campaign involves the xRAT (QuasarRAT) malware, which is disguised as legitimate adult game content to…

AhnLab Security Intelligence Center (ASEC) has identified a distribution campaign targeting Windows users through Korean web hard services. This campaign involves the xRAT (QuasarRAT) malware, which is disguised as legitimate adult game content to deceive users into downloading and executing harmful files.

Threat actors exploit the popularity of Korean web hard services for malware distribution. The xRAT campaign follows a pattern observed in previous campaigns, including njRAT, Remcos, UDP Rat, Korat, and XWorm malware. By disguising malicious payloads as legitimate software, games, and adult content, threat actors achieve high infection rates while evading initial detection.

The attack initiates when users download an adult game from a compromised web hard post. The ZIP file contains files such as "Game.exe," "Data1.Pak," "Data2.Pak," and "Data3.Pak." Users executing "Game.exe" unknowingly activate a malicious launcher. This launcher executes the real game launcher from "Data1.Pak," creating a semblance of legitimacy.

While the game operates, the malware is silently deployed in the background. Upon clicking the "Game Play!" button, the malware's infection chain begins. It copies files to hidden directories: "Data1.Pak" becomes "Play.exe" in the "Locales_module" folder, and "Data2.Pak" and "Data3.Pak" relocate to "C:\Users[User Account Name]\AppData\Local\Microsoft\Windows\Explorer" as "GoogleUpdate.exe" and "WinUpdate.db," respectively.

AhnLab Security Intelligence Center (ASEC) has identified a distribution campaign targeting Windows users through Korean web hard services.
نضال النعيم · Thehackingpost

"GoogleUpdate.exe" performs critical operations, decrypting "WinUpdate.db" using AES-based decryption to extract the final shellcode payload. It patches the EtwEventWrite() function in explorer.exe with a 0xC3 (RET) instruction, disabling Event Tracing for Windows (ETW) event logging.

The final payload injected into explorer.exe is xRAT, also known as QuasarRAT, an open-source remote access trojan with extensive capabilities. Once activated, xRAT can collect system information, perform keystroke logging, and download or upload files on the compromised system. These capabilities pose significant threats to both individual users and organizational security.

To mitigate risks, users should only download software from official vendor sites. Security teams are advised to implement endpoint detection and response (EDR) solutions and maintain updated systems with the latest security patches. AhnLab provides detection signatures, including File Detection for Data/Bin.Shellcode, Trojan/Win.Agent.C5834849, Trojan/Win.Loader.C5834845, and Trojan/Win32.Subti.C1663822, as well as Behavior Detection for Malware/MDP.Behavior.M1839.

Advertisement

The persistence of web hard-based malware distribution highlights the need for user awareness and strict software sourcing practices in combating cyber threats.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories