Good Game, Gone Bad: Xeno RAT Spread Via .gg Domains and GitHub
2024-06-24 • Hunt.io •
https://hunt.io/blog/good-game-gone-bad-xeno-rat-spread-via-gg-domains-and-github
Hunt observed XenoRAT distribution using gaming-themed .gg domains, a GitHub account posing as Roblox scripting tools, and a likely linked YouTube channel that instructed users to disable Windows Defender. The report notes prior links between XenoRAT and North Korea-linked activity, including an ASEC report on Dropbox delivery and an open directory likely run by Kimsuky that hosted the tool. The newly described infrastructure includes multiple gl.at.ply.gg controller domains, shared Developed Methods LLC IP space, and samples disguised as Roblox executors or Synapse X launchers. One related archive also delivered Quasar through portmap.io, showing the campaign mixed open-source RAT tooling with gamer-focused lures.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e9251ef1dd3ebe4f17acf0b3552e227… | 2024-06-24 | 2024-06-24 |
| HASH | 2051551c6c0f18eaf3c4cf45ffe6119… | 2024-06-24 | 2024-06-24 |
| HASH | 5e7138c7ee8a1de9d041804fd11ac0b… | 2024-06-24 | 2024-06-24 |
| HASH | a3254b90b2c6e12c29f7d9f538087da… | 2024-06-24 | 2024-06-24 |
| HASH | af68a0b9e9c58dcbdd2ede205c30537… | 2024-06-24 | 2024-06-24 |
| HASH | 707c68257c2ea97fa4591f58be326e1… | 2024-06-24 | 2024-06-24 |
| HASH | 38ce2a41d59a1bf0f3332fb867f4379… | 2024-06-24 | 2024-06-24 |
| HASH | 33ac2b2d228a1ec93b0ea70ffadb436… | 2024-06-24 | 2024-06-24 |
| HASH | 7c7408870da2fe079aa460fe0d237e1… | 2024-06-24 | 2024-06-24 |
| HASH | 029f3396c39f543dd984031eb82edcc… | 2024-06-24 | 2024-06-24 |