216.73.216.226

Notorious WrnRAT Delivered Mimic As Gambling Games

· Published 29/10/2024 21:32 · Modified 30/10/2024 21:31

Export JSON

Essential information

Published
29/10/2024 21:32
Modified
30/10/2024 21:31
Tags
2024-10-29 financial exploitation gambling korea multi-stage infection pyinstaller screen capture wrnrat
Related entities
5 observables, 11 techniques (mitre), 1 malware, 2 others

Description

Cybersecurity analysts have uncovered a sophisticated malware operation targeting online platforms. Threat actors are distributing the malware by disguising it as popular Korean games. The process involves a batch script, followed by a .NET-based dropper that installs and executes . The malware, developed using Python and packaged with , captures screenshots, collects system information, and can terminate specific processes. It also manipulates firewall configurations to evade detection. The primary motivation appears to be , with attackers potentially gaining unfair advantages in activities by observing players' actions in real-time.

External references