WebRAT malware is making a comeback with a particularly troubling distribution tactic: GitHub repositories posing as proof-of-concept exploits for recently published vulnerabilities. Attackers are taking advantage of the increased demand for test code, targeting researchers, developers, and cybersecurity professionals looking for authoritative technical information.

From cheats and cracks to targeted attacks
WebRAT is not new. Earlier this year, it was detected being distributed via pirated software and cheats for popular games such as Roblox, Counter Strike, and Rust. It is a backdoor with extensive capabilities and data theft, which has now been ported to more “professional” channels, significantly increasing its risk.
See also: Fake WhatsApp API package on npm steals messages
What WebRAT can do to victims' systems
According to analysis by Solar 4RAYS, WebRAT is capable of stealing credentials from Steam, Discord, and Telegram accounts, as well as data from cryptocurrency wallets. It also has the ability to monitor webcams, take screenshots, and collect sensitive information in real time, making it particularly dangerous for individuals and professionals.
Fake exploits based on real CVEs
Since September, WebRAT operators have been uploading repositories that allegedly exploit known vulnerabilities, such as serious bugs in Windows and WordPress. The repositories include detailed descriptions and technical details, creating the illusion of reliability. Kaspersky identified a total of 15 such repositories, all designed with a similar structure.
See also: MacSync Stealer bypasses Apple's malware protections

Content "written" by artificial intelligence
A particularly interesting element of the research is the assessment that the accompanying text in the repositories has been created with the help of artificial intelligence models. The uniformity, technical language and structure of the descriptions suggest automation, which reduces the cost for attackers and increases the speed of creating new traps.
How malware is installed
The fake exploits are distributed as password-protected ZIP files. Inside, they contain decoy files, a batch script, and a dropper named rasmanesc.exe. When executed, the dropper elevates privileges, disables Windows Defender, and downloads WebRAT from a predefined address. The malware then achieves persistence by making changes to the Registry, Task Scheduler, and system directories.
See also: Wonderland: Android malware combines dropper, SMS theft and RAT capabilities

An old tactic that remains effective
The use of fake exploits on GitHub is nothing new. Similar campaigns have been documented in the past, most recently the alleged “LDAPNightmare” exploit. Although the WebRAT repositories have been removed, there is no reason to rule out their reappearance under different names and accounts.
What professionals and enthusiasts should pay attention to
The incident highlights the importance of source verification and safe code testing. Any exploit or tool from an untrusted source should only be run in isolated, controlled environments. In an era where even security research can be turned into an attack vehicle, suspicion remains the most powerful defense.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
