Microsoft Threat Intelligence has identified a new threat involving trojanized gaming utilities, such as Xeno.exe and RobloxPlayerBeta.exe, which are being used to distribute a Windows remote access trojan (RAT). This malware campaign is targeting users by disguising itself as legitimate gaming tools.

Malware Distribution and Techniques

The initial phase of the attack involves the installation of a portable Java runtime and the execution of jd-gui.jar. The malware then leverages PowerShell and trusted Windows binaries, known as LOLBins, such as cmstp.exe, to download a payload named update.exe from domains like powercatdog and PythonAnywhere-hosted endpoints. This process ensures the malware can bypass traditional security measures.

Persistence and Defense Evasion

Once installed, the malware removes traces of the original downloader and adds exclusions in Microsoft Defender for its malicious files. It establishes persistence through scheduled tasks and a startup script called world.vbs. The final payload acts as a loader, runner, downloader, and remote access tool, granting attackers prolonged control over the infected system.

Security Recommendations

Microsoft Defender is capable of detecting this malware and its behavior patterns. However, organizations are advised to monitor outbound traffic, block the identified domains and IPs, and scrutinize or remove suspicious Defender exclusions, scheduled tasks, and startup scripts. Users are strongly cautioned against downloading or running unofficial game utilities shared in online chats or forums.

The Rats in the Wall

The Rats in the Wall download for free to PC or mobile

Explore a haunting mansion, uncover hidden truths, and unravel a chilling family mystery.

4
1030 reviews
2373 downloads

News and reviews about The Rats in the Wall

12 May 2025

Nier Collaboration Enhances The First Descendant's Appeal

Nier Automata fans rejoice as a new collaboration brings iconic 2B to The First Descendant, highlighting Nexon's dedication to enhance their gaming experience.

Read more

10 May 2025

Nexon Prepares for The First Descendant Season 3 Updates

Nexon is prioritizing major updates for The First Descendant's upcoming Season 3, focusing on balance and quality improvements as players anticipate new features and enhancements.

Read more

14 Apr 2025

Descendant: Nexon's Update Enhances Endgame Rewards

Nexon's hotfix for The First Descendant increases rewards in the Void Erosion Purge mode, easing restrictions and enhancing gameplay. The update aims to balance challenges and visual effects, broadening player engagement with augmented crafting materials.

Read more

09 Apr 2025

The First Descendant Faces Opposition After Latest Nerfs

Nexon's The First Descendant sees player decline and negative reviews on Steam after recent nerfs, contradicting earlier developer assurances.

Read more

10 Jul 2024

The First Descendant by Nexon Tops Steam Charts, Surpasses Elden Ring

The First Descendant by Nexon has swiftly climbed to the top position on Steam, overtaking well-known games such as Elden Ring and Counter-Strike 2. This rapid ascent highlights the game's growing popularity and strong market presence.

Read more