Security News > 2023 > July > HotRat: New Variant of AsyncRAT Malware Spreading Through Pirated Software

HotRat: New Variant of AsyncRAT Malware Spreading Through Pirated Software
2023-07-21 15:05

A new variant of AsyncRAT malware dubbed HotRat is being distributed via free, pirated versions of popular software and utilities such as video games, image and sound editing software, and Microsoft Office.

"HotRat malware equips attackers with a wide array of capabilities, such as stealing login credentials, cryptocurrency wallets, screen capturing, keylogging, installing more malware, and gaining access to or altering clipboard data," Avast security researcher Martin a Milánek said.

The attacks entail bundling the cracked software available online via torrent sites with a malicious AutoHotkey script that initiates an infection chain designed to deactivate antivirus solutions on the compromised host and ultimately launch the HotRat payload using a Visual Basic Script loader.

HotRat, described as a comprehensive RAT malware, comes with nearly 20 commands, each of which executes a.NET module retrieved from a remote server, allowing the threat actors behind the campaign to extend its features as and when required.

"Despite the substantial risks involved, the irresistible temptation to acquire high-quality software at no cost persists, leading many people to download illegal software," Milánek said.

"Therefore, distributing such software remains an effective method for widely spreading malware."


News URL

https://thehackernews.com/2023/07/hotrat-new-variant-of-asyncrat-malware.html