Thursday, August 27, 2026

xRAT Malware Targets Windows Users via Fake Adult Game

AhnLab Security Intelligence Center (ASEC) has uncovered a dangerous distribution campaign targeting Windows users through Korean web hard services.

Threat actors are leveraging xRAT (QuasarRAT) malware, disguising it as legitimate adult game content to deceive unsuspecting users into downloading and executing malicious files.

Korean webhard services have become a prime vector for malware distribution, with threat actors consistently exploiting their popularity among users.

The malicious actors behind this xRAT campaign follow a pattern that has been documented across multiple previous campaigns involving njRAT, Remcos, UDP Rat, Korat, and XWorm malware families.

By disguising payloads as legitimate software, games, and adult content, these threat actors maintain high infection rates while evading initial detection.

The Deceptive Distribution Mechanism

The attack begins when users download what appears to be an adult game from a compromised or fraudulent webhard post. Upon extraction, the ZIP file contains seemingly innocuous files, including “Game.exe,” “Data1.Pak,” “Data2.Pak,” and “Data3.Pak.”

File structure.
File structure.

Users naturally execute “Game.exe” expecting the game to launch. However, this executable serves as a malicious launcher rather than the actual game application.

The initial launcher executes the genuine game launcher from “Data1.Pak,” creating a false sense of legitimacy.

While the game runs, the malware silently deploys in the background a sophisticated social engineering technique that keeps users unaware of the infection.

When users click the “Game Play!” button, the malware initiates its infection chain.

The launcher copies files to hidden system directories: “Data1.Pak” becomes “Play.exe” in the “Locales_module” folder, while “Data2.Pak” and “Data3.Pak” are relocated to “C:\Users[User Account Name]\AppData\Local\Microsoft\Windows\Explorer” with the names “GoogleUpdate.exe” and “WinUpdate.db” respectively.

The “GoogleUpdate.exe” component performs critical malicious operations. It locates “WinUpdate.db” and applies AES-based decryption to extract the final shellcode payload.

Notably, this component patches the EtwEventWrite() function in explorer.exe with a 0xC3 (RET) instruction, effectively turning off Event Tracing for Windows (ETW) event logging a key defense mechanism that security tools rely upon for threat detection.

xRAT Capabilities and Impact

The final payload injected into explorer.exe is xRAT, also known as QuasarRAT, an open-source remote access trojan with extensive malicious capabilities.

 Event log disabled code.
 Event log disabled code.

Once activated, xRAT can collect sensitive system information, perform keystroke logging to capture credentials and sensitive data, and download or upload files on the compromised system.

These capabilities make xRAT a serious threat to both individual users and organizational security.

Given the active distribution of malware through Korean webhard services and similar file-sharing platforms, users must exercise extreme caution when downloading executable files from these sources.

The primary defense strategy involves obtaining software exclusively from official vendor websites rather than third-party file-sharing platforms.

Security teams should implement endpoint detection and response (EDR) solutions and keep systems updated with the latest security patches.

AhnLab has provided the following detection signatures: File Detection includes Data/Bin.Shellcode, Trojan/Win.Agent.C5834849, Trojan/Win.Loader.C5834845, and Trojan/Win32.Subti.C1663822. Behavior Detection includes Malware/MDP.Behavior.M1839.

The persistence of webhard-based malware distribution underscores the importance of user awareness and maintaining strict software sourcing practices in the ongoing battle against cyber threats.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

AWS Security Teams Can Correlate CloudTrail, VPC and Route 53 Logs to Detect Attacks

AWS security teams can improve detection of multi-stage intrusions...

Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency

Suspected Chinese-speaking operators exploited the critical ownCloud flaw CVE-2023-49105...

CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power

AI infrastructure is rapidly becoming a high-value enterprise attack...

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised...

CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News