Malware botnet installing NiceRAT
Essential information
Description
This report discusses a botnet that has been active since 2019, distributing various malware such as NiceRAT, Nitol, and NanoCore. The botnet is spread through disguised cracked programs, shared on domestic file-sharing sites and blogs, posing as genuine software activators or game server tools. Once infected, the malware connects to command-and-control (C&C) servers and installs additional payloads like NiceRAT, which is a Python-based open-source remote access trojan that steals system information, browser data, and cryptocurrency wallets.