Hacking

Trojanized Gaming Tools Deliver Stealthy Java RAT

Published  ·  3 min read

Threat actors have found a new way to hook gamers: they're slipping remote access trojans (RATs) into what look like handy gaming utilities, then spreading them through browsers, Discord chats, forums, and other spots where players hang out.

Microsoft Threat Intelligence flagged the campaign recently, noting how a sneaky downloader sets up a portable Java runtime environment on the victim's machine and then runs a malicious JAR file cleverly named jd-gui.jar (masquerading as the popular Java decompiler tool). To stay under the radar, the downloader leans on PowerShell scripts and legitimate Windows tools like cmstp.exe (a classic living-off-the-land binary), for execution without tripping alarms.

Once malware enters a computer, it cleans up by deleting the original downloader and placing exclusions in Microsoft Defender for its various components. It persists on your computer through a scheduled task, along with a start-up script called world.vbs, which sets up for the main payload, which is a multi-stage, fully functional piece of malware that acts as both a loader and downloader and contains a fully functional RAT (remote access tool).

The RAT phones home to a command-and-control server at 79.110.49[.]15, letting attackers pull data out, drop more tools, or just poke around at will.

Microsoft's advice for anyone who suspects they've run one of these fakes: check your Defender exclusions and scheduled tasks carefully, nuke anything suspicious, isolate the machine, and reset credentials for any accounts that were logged in during the incident.

This isn't the only RAT making headlines lately. Security firm BlackFog just detailed Steaelite, a fresh Windows RAT family that popped up on underground forums back in November 2025, billed as the "best Windows RAT" with full undetectability claims. It works on both Windows 10 and 11 and stands out by bundling data theft with ransomware deployment, all managed from one slick browser-based dashboard. Operators can remote-execute code, manage files, stream live video from the webcam, grab microphone audio, monitor the clipboard, steal passwords and credentials, enumerate installed programs, track location, open URLs, launch DDoS attacks, compile VB.NET payloads, and more.

What makes Steaelite particularly nasty is how it lowers the bar for double extortion: a single actor can browse files, exfiltrate sensitive docs, harvest logins, then flip the switch to ransomware, all without switching tools. Features include killing off rival malware, disabling or excluding Defender, installing persistence, chatting directly with victims, spreading via USB, changing wallpapers, bypassing UAC, and even an upcoming Android ransomware module. It's the kind of all-in-one kit that turns opportunistic hits into streamlined, high-impact operations.

Threat hunters have also spotted two other emerging RATs: DesckVB RAT and KazakRAT. Both offer broad remote control, with some modular capabilities that can be toggled after infection. There is a suspicion that KazakRAT has been used by a state-sponsored hacking group against organizations in Kazakhstan and Afghanistan since at least mid-2022; this is indicative of the continued evolution from simple backdoor types of RAT to more sophisticated/capable RATs and platforms designed to facilitate the work of the cybercriminals who use them (and complicate the lives of everyone else).

If you're a gamer downloading "cheats," trainers, or utilities from unofficial sources, the risk-reward math has gotten a lot worse lately. Stick to official channels, run everything through VirusTotal if you're unsure, and keep an eye on those scheduled tasks, because one innocent-sounding .exe can open the door wide.

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067