• News/
  • https://www.bleepingcomputer.com/news/security/webrat-malware-spread-via-fake-vulnerability-exploits-on-github/

WebRAT malware spread via fake vulnerability exploits on GitHub

BleepingComputer
·
Bill Toulas
·
Published Dec 23, 2025
·
Updated

The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities. Previously spread through pirated software and cheats for games like Roblox, Counter Strike, and Rust, WebRAT is a backdoor with info-stealing capabilities that emerged at the beginning of the year. According to a report from Solar 4RAYS in May, WebRAT can steal credentials for Steam, Discord, and Telegram accounts, as well as cryptocurrency wallet data. It can also spy on victims through webcams and capture screenshots. Since at least September, the operators started to deliver the malware through carefully crafted repositories claiming to provide an exploit for several vulnerabilities that had been covered in media reports. Among them were: Security researchers at Kaspersky discovered 15 repositories distributing WebRAT, all of them providing information about the issue, what the alleged exploit does, and the available mitigations. Due to the way the information is structured, Kaspersky believes that the text was generated using an artificial intelligence model. The malware has multiple methods to establish persistence, including Windows Registry modifications, the Task Scheduler, and injecting itself into random system directories. Kaspersky researchers say that the fake exploits are delivered in the form of a password-protected ZIP file containing an empty file with the password as its name, a corrupted decoy DLL fil...

Read full article

Affected Software

2 affected components
Kaspersky WebRAT
GitHub repositories
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The main topic of the article is the distribution of WebRAT malware through fake vulnerability exploits hosted on GitHub.

2

What security implications are discussed?

The article highlights the risk of downloading malware disguised as proof-of-concept exploits for recent vulnerabilities.

3

What products or software are affected?

The affected software includes GitHub repositories hosting the malware and Kaspersky's WebRAT malware.

4

How is the WebRAT malware typically distributed?

WebRAT malware has previously been spread through pirated software and gaming cheats before its recent distribution via GitHub.

5

What should users be cautious about regarding GitHub repositories?

Users should be cautious of GitHub repositories claiming to provide exploits, as they may host malicious content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203