RAT malware spreading in Korea through webhards and torrents

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,176
An ongoing malware distribution campaign targeting South Korea is disguising RATs (remote access trojans) as an adult game shared via webhards and torrents.

The attackers are using easily obtainable malware such as njRAT and UDP RAT, wrap them in a package that appears like a game or other program, and then upload them on webhards.

WebHard is a popular online storage service in Korea, preferred mainly for the convenience of direct downloads.

Users end up at webhards through Discord or social media posts, but popular storage repositories enjoy a steady stream of daily visitors due to the content that is shared.

As reported by analysts at ASEC, threat actors are now using webhards to distribute a UDP RAT that is disguised as ZIP file containing an adult game.
When extracted, the archive contains a 'game.exe' launcher, which is actually the UDP rate malware.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top