Good Game, Gone Bad: Xeno RAT Spread Via .gg Domains and GitHub

2024-06-24 Hunt.io

https://hunt.io/blog/good-game-gone-bad-xeno-rat-spread-via-gg-domains-and-github

Thumbnail for Good Game, Gone Bad: Xeno RAT Spread Via .gg Domains and GitHub

Hunt observed XenoRAT distribution using gaming-themed .gg domains, a GitHub account posing as Roblox scripting tools, and a likely linked YouTube channel that instructed users to disable Windows Defender. The report notes prior links between XenoRAT and North Korea-linked activity, including an ASEC report on Dropbox delivery and an open directory likely run by Kimsuky that hosted the tool. The newly described infrastructure includes multiple gl.at.ply.gg controller domains, shared Developed Methods LLC IP space, and samples disguised as Roblox executors or Synapse X launchers. One related archive also delivered Quasar through portmap.io, showing the campaign mixed open-source RAT tooling with gamer-focused lures.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e9251ef1dd3ebe4f17acf0b3552e227… 2024-06-24 2024-06-24
HASH 2051551c6c0f18eaf3c4cf45ffe6119… 2024-06-24 2024-06-24
HASH 5e7138c7ee8a1de9d041804fd11ac0b… 2024-06-24 2024-06-24
HASH a3254b90b2c6e12c29f7d9f538087da… 2024-06-24 2024-06-24
HASH af68a0b9e9c58dcbdd2ede205c30537… 2024-06-24 2024-06-24
HASH 707c68257c2ea97fa4591f58be326e1… 2024-06-24 2024-06-24
HASH 38ce2a41d59a1bf0f3332fb867f4379… 2024-06-24 2024-06-24
HASH 33ac2b2d228a1ec93b0ea70ffadb436… 2024-06-24 2024-06-24
HASH 7c7408870da2fe079aa460fe0d237e1… 2024-06-24 2024-06-24
HASH 029f3396c39f543dd984031eb82edcc… 2024-06-24 2024-06-24

Related Reports

« Back