Automatically translated.View original post

Malware xRAT claims to be a lewd game

Malware xRAT claims to be a lewd game. Tricked into embedded on a Windows system machine.

Playing pornographic video games or finding pornographic videos to watch is, although morally and in some places, illegal, it must be recognized as human nature as a whole, so that in many countries, even at the risk of finding contraband to watch, it often embraces the risk, but some risks may be more dangerous than recruiters expect, such as in this news.

According to a report by the website Cyber Security News, it has mentioned the detection of a remote access trojan malware distribution campaign called xRAT, also known as QuasarRAT. The campaign focuses on tackling a group of users of the Windows operating system in South Korea by impersonating pornographic video games through social engineering.

In spreading this malware, hackers compress fake game files with malware hidden in the Zip file format, which inside the file contains many different files that look similar to normal games, such as Game.exe, Data1. Pak and other supporting files. This compressed file is uploaded on Webhard, a popular file depository service in South Korea. Web services in this format, when new files are uploaded and interesting files are named, people buy files from the platform. The uploader gets a share of the file value. This is called. In addition to tricking the victim into downloading the malware file from the naming of the interesting file, they earn revenue. This is called the whole box.

After the victim downloads a fake game file and unfolds it and runs the Game.exe file, it will find a menu screen similar to the game launcher or the launcher. But after the victim presses the Play button to play the game, the malware will start immediately by copying the Data1.Pak file to the Locales _ module folder under the name Play.exe. Meanwhile, the malware will copy Data2.Pak and Data3.Pak files to the Windows Explorer folder under the names GoogleUpdate.exe and WinUpdate.db.

After all files have been deployed in a given folder, the malware will run the GoogleUpdate.exe file. The file will search for WinUpdate.db files in the same folder and decryption them. Using the AEC algorithm to extract the last Shellcode malware code and shoot the code to a process called explorer.exe, which is an important Windows process, giving the malware the highest level of access to the system (SYSTEM). In addition, to firing the code into the process, the EtwEventWrite function is used with the Return Instruction command to disable it. Windows Logging's Event Tracing makes it difficult to detect the installation and operation of malware. It also prevents detection by various cyber protection tools on board, so that it can be called a stabilization technique or a type of Persistence.

After everything is ready, it will actually shoot down the last code. This is the code of the xRAT malware that is effective at stealing a variety of data - storing system data, secretly trapping keyboard data, and smuggling file theft back to hackers or even sending files from hackers into the machine. In the wake of the misfortune, the source has warned that users are extremely careful to download files for the security of the data and the machine.

# Trending # Lemon 8 Howtoo # Drug sign with lemon8 # lemon 8 diary # freedomhack

1/29 Edited to

... Read moreจากประสบการณ์ส่วนตัวที่เคยพบเจอเหตุการณ์มัลแวร์หลอกลวงในลักษณะคล้าย ๆ กัน สิ่งที่ชัดเจนคือการที่แฮกเกอร์มักจะใช้กลวิธีหลอกล่อที่ดูน่าสนใจหรือถูกใจเป้าหมายมากที่สุด เช่น การแอบอ้างเป็นไฟล์เกมที่ได้รับความนิยม หรือไฟล์สื่อบันเทิงประเภทต่าง ๆ ซึ่งทำให้หลายคนคลิกดาวน์โหลดโดยไม่ทันระวัง การใช้วิศวกรรมสังคม (Social Engineering) เช่นนี้ถือเป็นเทคนิคที่แฮกเกอร์เลือกใช้ได้อย่างมีประสิทธิภาพมาก เพราะมันล่อใจให้ผู้ใช้เปิดไฟล์ที่อาจเป็นอันตรายได้ง่าย ๆ แม้เราจะรู้ว่าไฟล์ที่ดาวน์โหลดมาจากแหล่งที่น่าสงสัยก็ควรหลีกเลี่ยง แต่ในความจริงมักมีข้อยกเว้นที่หลายคนยอมเสี่ยงเพื่อความสนุกหรือความบันเทิง นอกจากนี้มัลแวร์ xRAT มีความน่าสนใจตรงที่มันใช้โค้ดขั้นสูง เช่น อัลกอริทึ่ม AES เพื่อถอดรหัสโค้ดมัลแวร์ และซ่อนตัวใน Process ของ Windows ที่สำคัญอย่าง explorer.exe พร้อมทั้งปิดการทำงานของ Event Tracing เพื่อป้องกันการตรวจจับ การใช้เทคนิคแบบนี้นับว่าน่ากลัวและยากต่อการตรวจสอบ การป้องกันที่ดีที่สุดคือการมีสติและระมัดระวังอย่างสูงในการดาวน์โหลดไฟล์ทุกชนิด โดยเฉพาะไฟล์จากแหล่งที่ไม่น่าเชื่อถือ รวมถึงระวังไฟล์ ZIP ที่อาจซ่อนไฟล์ปฏิบัติการ (exe) อันตรายไว้ สำหรับผู้ใช้งาน Windows ควรติดตั้งโปรแกรมป้องกันไวรัสและมัลแวร์ที่ทันสมัย อัปเดตระบบปฏิบัติการและซอฟต์แวร์อย่างสม่ำเสมอ รวมถึงหลีกเลี่ยงการเปิดใช้งานไฟล์หรือโปรแกรมที่ไม่คุ้นเคย และถ้าเป็นไปได้ควรสำรองข้อมูลสำคัญไว้ในที่ปลอดภัยเป็นประจำ ถึงแม้ว่าวิดีโอเกมหรือเนื้อหาบันเทิงบางประเภทอาจมีความก้ำกึ่งทางศีลธรรมแต่เราก็ไม่ควรเสี่ยงเอาชีวิตและข้อมูลส่วนตัวไปแลกกับความบันเทิง เพราะมัลแวร์เหล่านี้อาจช้อนเลือดข้อมูล รหัสผ่าน หรือแม้แต่ไฟล์ส่วนตัวของเราไปใช้ในทางที่ผิดได้ ท้ายที่สุด อยากให้ทุกคนตระหนักถึงความเสี่ยงและเลือกใช้อินเทอร์เน็ตอย่างระมัดระวัง เพราะความปลอดภัยของเราเริ่มต้นจากการตัดสินใจที่ดีในการใช้ไฟล์และแอปพลิเคชันต่าง ๆ

Related posts

It's no secret that Karol G just slayed the #Grammys #Glambot . #AwardsSeason
user6854050772614

user6854050772614

11 likes

A young woman with long dark hair, wearing a pink satin shirt, smiles at the camera while sitting at a table. Overlay text reads: 'Tools and sites I use as a cybersecurity student to progress my skills and keep me interested in studying'.
A screenshot of 'The Hacker News' website, displaying various cybersecurity news articles from January 2025, including topics like vulnerabilities, malware, cyber espionage, and AI jailbreak methods. An ad for Zscaler and a banner for CIS Hardened Images are also visible.
A screenshot of the O'Reilly learning platform, showing various books and expert playlists related to AI, engineering, and data. Overlay text highlights the subscription cost ($50/month or $499/year) and its value for accessing books and live events.
Tools and sites I use as a cybersecurity student 🌸
#cybersecuritystudent #cybersecurity #techgirlie
LexiStudies

LexiStudies

107 likes

3 cybersecurity jobs that pay well
1. Security Analyst - What They Do: Monitor networks for vulnerabilities, investigate breaches, and implement security measures. - How to Start: - Obtain certifications like CompTIA Security+ or CySA+. - Gain experience with tools like SIEM (e.g., Splunk). - Start in an I
vedha | career tips (tech) 👩‍

vedha | career tips (tech) 👩‍

633 likes

Free SVG files for Cricut Design Space. If you’re dealing with crafter’s block, this website has tons of free SVG downloads to spark new project ideas for shirts, stickers, bookmarks, and more. Save this for your next Cricut project and start creating again 💕 #designinspo #creativeart
VlunaWorks

VlunaWorks

5 likes

Check out this website that helps you when you’re feeling uninspired! I walk you thru the process of downloading the svg file to taking it to cricut design space! Happy crafting. #designinspo #creativeart #cricutprojects #svgfiles #CricutTips
VlunaWorks

VlunaWorks

46 likes

A person with long dark hair and a straw hat walks through a sunny public square. Overlay text reads "CYBERSECURITY CAREER Tips to get started," introducing advice for a career in cybersecurity.
A person in a white dress walks on a path next to green bushes. Overlay text advises to "Build a Strong Technical Foundation" by learning networking basics, operating systems, and scripting languages.
People walk across a street with benches and trees in the background. Overlay text suggests to "Get Hands-On Experience" through CTF competitions, cybersecurity challenges, and setting up a home lab.
Tips for pursuing a career in cybersecurity
1. Build a Strong Technical Foundation A solid understanding of systems, networks, and programming is essential for identifying and mitigating security threats. • Learn networking basics (e.g., TCP/IP, firewalls, VPNs). • Gain familiarity with operating systems (Windows, Linux)
vedha | career tips (tech) 👩‍

vedha | career tips (tech) 👩‍

132 likes

Why I switched to taking notes on my iPad
I used to love writing in notebooks, but after switching to my iPad, I can confidently say I’m never going back! Here’s why: ✨ Cuter Notes – Let’s be real…aesthetic notes make studying more enjoyable! I can use custom colors, cute stickers, and different handwriting styles to make my notes visua
Rebecca R.

Rebecca R.

263 likes

Squid Game Cookies in Sandboxels
#game #gaming #baking #squidgame #dalgona #games
R74n

R74n

87 likes

#batman is not the world’s greatest detective in fact he’s like the latest detective to find the guild. The world’s greatest detective is #detectivechimp #dccomics
Dan!

Dan!

3 likes

Basic IT Knowledge: Cybersecurity Basics
🔒 BASIC IT KNOWLEDGE: CYBERSECURITY BASICS 🔒 You lock your front door. You protect your wallet. So why wouldn’t you protect your digital life too? 👀 Cybersecurity is all about protecting your devices, accounts, and personal information from online threats. That means staying safe fro
ITwDee

ITwDee

1 like

Elite Hacker Destroyed His Empire By Forgetting On
Bro, I really forgot to use a VPN 💀 #hacker #cybercrime #fail #tech #arrestedstupidly
arrestedstupidly

arrestedstupidly

1 like

Olas just wandeing off at Disneyland Paris at the New World of Frozen coming next March! Beyond cute #disneyland #WorldOfFrozen #frozen #disneyadventureworld #disneylandparis
gez9knzxvzz

gez9knzxvzz

1 like

Files Copied to USB Drive Disappear? Lets Recover
Copied files to your USB drive, then they vanished? This issue is often caused by hidden files, unsafe ejection, corruption, or failing flash storage. This guide shows how to reveal hidden files, repair USB errors, and recover missing data safely before it gets overwritten. #usb #datarecovery
XanthusTechCore

XanthusTechCore

4 likes

😫 Wanting to quit your 9-5?
Becoming a Pinterest Manager might be for you! In less than a year, I went from earning $2K at my 9-5 to over $4K/month with Pinterest management alone. Now, with all the different skills and platforms I lesrned, I make anywhere from $12-15K A MONTH! Back then, I knew I had to do something
Bria | Social, Design, & AI

Bria | Social, Design, & AI

482 likes

A desk setup with a curved monitor displaying a pink grid wallpaper and pixel art juice boxes. An overlay on the screen reads "How to Make Your PC Run Faster – 5 Easy Tips!". A keyboard, laptop, and drink are on the desk, with a Lemon8 watermark.
A desk setup with a monitor displaying tips for a faster PC, including "Upgrade Your Storage & RAM," "Keep Your Drivers & OS Updated," and "Check for Malware & Viruses." An overlay highlights "Upgrade Your Storage & RAM and more!" with a Lemon8 watermark.
A desk setup with a monitor displaying instructions for "Disable Startup Programs" and "Clean Temporary Files." The screen shows steps like using Task Manager and deleting temporary files. A keyboard, laptop, and drink are on the desk, with a Lemon8 watermark.
⚡ How to Make Your PC Run Faster – 5 Easy Tips! 🖥️🔥
💡 1. Disable Startup Programs 🚀 Too many apps launching at startup slow down your PC! ✅ Open Task Manager (Ctrl + Shift + Esc) ✅ Go to the Startup tab ✅ Disable unnecessary apps to speed up boot time 💡 2. Clean Temporary Files 🗑️ Over time, junk files slow your system down. ✅ Press Win
skaeszun

skaeszun

284 likes

A black journal featuring a white drawing of Jack Skellington's face and stars, held by a hand.
A journal spread featuring handwritten lyrics for "Sally's Song" from The Nightmare Before Christmas, adorned with various character stickers from the movie.
A journal spread with religious quotes and Bible verses about hope, rejoice, and faith, decorated with cross stickers and floral designs.
Journal Spreads ive done recently
okay its been a few months but so far i did great with all the stickers i love buyings stickers now as a comfort thing idk how to say it ig? but overall my journal spreads look so good so far i hope yall like it js as much as i do<3 anywho im waiting for an upcoming concert to add i cant wait to
mal<3

mal<3

162 likes

How to Make a Dyson Sphere in Sandboxels
#dysonsphere #science #sciencegames #gaming #pixelart
R74n

R74n

7 likes

If you’re staring at Cricut Design Space with zero ideas this is for you! This free SVG website is perfect when you need inspiration fast. Save & share with your crafty bestie 💖 #designinspo #creativeart #DesignProcess #cricutprojects #CricutTutorial
VlunaWorks

VlunaWorks

2 likes

Free Games! ✅
Free Games! ✅ Yes it’s trusted by many people and it’s the best in the industry! And no malware or virus! Follow for more value! 😉 #freegames #pcgamers #steamgames #gamer #tech
Tech With Unes

Tech With Unes

8 likes

#anime #animetiktok #aimanga #animerecommendations #fyp
eodrlg

eodrlg

16 likes

A vibrant cover image featuring Anjali Viramgama amidst confetti, with the title "Top Cybersecurity Certificates." It highlights key certifications for advancing skills and knowledge in cybersecurity.
A card detailing the Certified Information Security Manager (CISM) certification. It explains CISM focuses on managing information security programs, covering risk management, governance, and incident response.
A card detailing the Certified Ethical Hacker (CEH) certification. It explains CEH focuses on ethical hacking and penetration testing, covering topics like network scanning, malware threats, and social engineering.
Top Cybersecurity Certificates
There are several reputable cybersecurity certifications that can help you advance your skills and knowledge in the field of cybersecurity. 1. Certified Information Systems Security Professional (CISSP): - CISSP is a globally recognized certification that covers a wide range of cybersecurit
anjali.gama

anjali.gama

112 likes

A tutorial title card for 'Free Retro Console Games on MacOS' featuring a browser window showing 'OpenEmu.org' and illustrations of a retro handheld console and a joystick.
A screenshot of the OpenEmu website (openemu.org) in a Firefox browser, with an arrow pointing to the 'Download Now' button for 'Step 1: Download OpenEmu Emulator'.
A screenshot showing a Finder window with OpenEmu files, a pop-up to 'Move to Applications folder', and instructions for 'Step 2: Unzip and Open app' and 'Step 3: Move to Applications Folder', including security settings advice.
✨Retro Game Emulator for MacOS✨
Hey gamers! Setting up a game emulator on MacOS can seem daunting, but I've got you covered! I've created a step-by-step guide to help you get started. 🎮✨ Swipe through the photos above to see detailed screenshots with instructions. Whether you're a newbie or a seasoned gamer, thi
Miroak

Miroak

64 likes

Back Up Outlook Emails to an External Hard Drive
Need to back up your Outlook emails to an external hard drive? Here are 2 simple methods to help you out. Download AOMEI Backupper and give it a try! #backup #outlook #externalharddrive
SmoothTechie

SmoothTechie

1 like

A colorful Disney tattoo of Stitch from Lilo & Stitch on an arm, featuring a watercolor-style blue and purple splatter background. The character is depicted with a wide, happy grin and outstretched arms, showcasing a vibrant and playful design.
A Disney tattoo on an arm featuring Thumper from Bambi, sitting among purple and blue flowers and tall grass. The tattoo includes the text "Macushla R.I.P. Johnny" below the character, rendered in a traditional tattoo style.
A traditional-style Disney tattoo on a leg depicting Esmeralda from The Hunchback of Notre Dame. She is shown in a flowing purple dress, holding a large crescent moon or hoop, surrounded by golden stars. The text "From my flash! Tiny blast over" is visible.
🏰✨Disney Tattoos✨🏰
Did you know, I’m a HUGE Disney nerd! It’s always a treat whenever I get to do something based on Disney, small or big, flash or custom 🥰 Here’s just a small compilation of some of my favorites! #disney #disneytattoo #tattoo #tattooartist #traditionaltattoo
Malware 🔜 FC

Malware 🔜 FC

375 likes

ERROR ERROR ERROR ERROR ERROR
🔺️!!!Flashy!!!🔺️ Um guys... Something is definitely wrong with my tablet 😬😨 #rewritesonic #malware #sonicexe #sonicthehedgehog #sonicfanart
EmK & Fidgi

EmK & Fidgi

2 likes

The Podcast Invite Scheme! Always remember - it’s not your fault ♥️ this happens to so many people. Most importantly: STAY SUSPICIOUS OF EVERYTHING 🥰💕 #podcastinvite #podcast #creator #storytime #scheme
Chloe

Chloe

71 likes

You need TikTok ?
Here is how you can download TikTok if you need help with and apple phone just ask me I can help with Apple phone you need to change your region on the Apple Pay store
Ali

Ali

10 likes

SOS!!! Wha do you do if you click a phishing email link… two times?!? So far I have: 1, added two factor sign on 2, changed my passwords 3, stress cried and spiraled But for real. What do you do… how do I know if there is now malware (? Is that what it’s called ?) living on my computer?!?
Alexandra Wildeson

Alexandra Wildeson

2 likes

An image expressing frustration with Riot Games, featuring "I Hate Riot!!" text over League of Legends characters. A Riot Vanguard notification states, "Vanguard has blocked something from loading on your machine," reflecting the user's issues with the game client and anti-cheat software.
I Hate Riot Client & Vanguard!!
As much as i like League of Leguends it pisses me off how i can't delete Riot Client and Vanguard so i can redownload LoL because i keep getting erros whenever i try to log in. They are SO damn hard to delete that some people are calling them Spyware/Malware and i'm starting to believe t
Raine🌈✨️

Raine🌈✨️

1 like

A hand holds a pink iPhone with text 'Tech 101 For Beginners' and 'Tips to help Non-Tech Savvy Users,' accompanied by laptop and phone app icons, against a brick background.
A pink iPhone in its box, illustrating the tip to 'Keep Your Devices Updated' with text explaining why updates help and advising to enable automatic updates.
An iPhone screen displaying app icons and display settings, accompanying the tip to 'Use Strong, Unique Passwords' with reasons why and advice on using combinations and password managers.
Tech Hacks For Beginners 📲💻😬
I have some great tips for non-tech savvy tech users. I know these tips will help you learn your tech more quickly and effectively. 1. Keep Your Devices Updated Why It Helps: Updates often contain security patches and improvements that help your device run smoothly. Tip: Enable automatic updat
Joy 📚

Joy 📚

282 likes

A hand holds a smartphone displaying a red warning triangle with an exclamation mark. Overlay text reads, 'FBI Warns Against Replying to Scam Texts,' emphasizing the danger of suspicious messages.
FBI Warns Against Replying to Scam Texts
The FBI is urging smartphone users to never reply to suspicious texts or calls, especially those claiming to be from government officials—often crafted to manipulate victims into handing over passwords or clicking malicious links. Scammers are increasingly impersonating senior U.S. officials via sm
Sylvia Lustre

Sylvia Lustre

4 likes

Unable to Initialize Hard Drive? Fix it Now
Find out how you can fix this issue and initialize your hard drive with ease using Partition Assistant, ensuring no data is lost during the process. #hdd #fix #repair #disk
SmoothTechie

SmoothTechie

0 likes

Amber 💋
I smell like a cloud above a tropical island. light, sweet, warm, refreshing and clean ⭐️Overall rating: 5/5 also #dollartreefinds this lotion smells amazing, idk what it's duping, but omg it's great. Atlanta
✨ Malware Noir ✨

✨ Malware Noir ✨

0 likes

🚨 16 Billion passwords leaked - the largest breach ever 🚨 Here is how it happened and what you can do to be safe. #news #databreach #cybersecuritytips #onlinesafety
Cybersecurity Girl

Cybersecurity Girl

126 likes

Never plug your phone or computer into usb plugs in hotels or airports here’s why 👇🏼 A USB port doesn’t just deliver power, it can also transfer data. A compromised hotel USB outlet could secretly install malware on your phone or copy your data without you realizing it. Hotels, airports, and o
Cybersecurity Girl

Cybersecurity Girl

151 likes

The image shows a man resembling Donald Trump speaking, with large red 'X' marks over text that reads 'QFS REDEMPTION CENT' and a warning about setting up a QFS account elsewhere. Below, text promotes 'THE WAVE OF CHANGE IS HERE!!' and lists steps to register a QFS account, purchase XLM & XRP, and apply for a QFS card.
Fake false lies
The statement you have shared appears to originate from a message promoting a purported “Quantum Financial System” (QFS), urging individuals to establish accounts, convert substantial portions of their assets, and invest in specific cryptocurrencies. As a professional inquiry into this topic warran
Dragonak1754

Dragonak1754

3 likes

A person's hands type on a laptop keyboard, with text overlaying the image stating '10 Online jobs That's pays $50-$100 per hour' and 'Swipe >>'.
Hands type on a laptop, displaying three online jobs: Media Buyer, Public Relations Manager, and Business Consultant, with their hourly rates and descriptions.
Hands type on a laptop, showing three online jobs: Cybersecurity Developer, AI Professional, and Machine Learning Engineer, with their hourly rates and descriptions.
10 online jobs that pays $50-$100 per hour!!
Want to earn $50-$100 per hour from the comfort of your own home? Check out these 10 online jobs that can help you achieve your financial goals! Ready to get started? Share your favorite online job or skill in the comments below! Let's get paid! Tag a friend who needs to know about these high-
Alesha

Alesha

16 likes

Day 3 of 31: 31 days to a safer you. Did you know hackers can turn on your webcam without you ever noticing? 🎥👀 it happens when malware sneaks onto your device and gives cybercriminals access to your camera. That means your most private moments could be exposed. ✅ Here’s how to protect yours
Cybersecurity Girl

Cybersecurity Girl

22 likes

A few updates to my journal 🖤🤗
#journalthrough #journal
mal<3

mal<3

16 likes

THE HASHTAGS ARE FOR ATTENTION! COMMENT YOUR FAVE FLAVOR OF JUICE OR SOMETHING! #wlw #techtok #blacktechtok #fyp
Bre’ 🍉🇨🇩🇵🇸

Bre’ 🍉🇨🇩🇵🇸

2 likes

30+ WordPress Plugins Used In Supply Chain Attack
30+ WordPress Plugins Used In Supply Chain Attack | Wordfence Security News Clip | April 13, 2026 A buyer acquired more than 30 WordPress plugins through the Flippa marketplace after purchasing the Essential Plugin portfolio for a six-figure sum. The buyer's first code commit was a backdoor
Wordfence

Wordfence

1 like

A laptop screen displays the Cool Math Games website, with the URL visible. A cursor hovers over the logo, and text overlay reads 'my favorite Nostalgic Gaming Website' with a Saturn icon.
A laptop screen shows a list of 'Papa's' cooking games on Cool Math Games, including Pizzeria, Freezeria, and Burgeria. Text overlay says 'The best games on the site tbh', with heart doodles highlighting some titles.
A laptop screen displays the game 'Bloxorz' on Cool Math Games, showing the start menu. Text overlay states, 'This game was one of the most popular at my school. I still love the vibes and the music.'
my favorite nostalgic gaming website...💻🕹🎲
Did anyone else get to play this on the computers at school!? #letschat #nostalgicgaming #embracevulnerability #Lemon8Diary #childhoodmemories #girlhood #gamergirl #websites #throwback #schoolmemories
CrystalViolet🫧

CrystalViolet🫧

45 likes

See more