Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantloader-delivery-mechanismdefense-evasion-methodpersistence-method

Trojanized Gaming Utilities Deliver Java-Based RAT via Browser and Chat Platforms

Updated 3mo agoFirst seen Feb 27, 20265 sources

Microsoft Threat Intelligence reported an active malware campaign targeting gamers by distributing trojanized gaming utilities through browsers and chat platforms, leading victims to execute a multi-stage downloader that ultimately installs a Java-based remote access trojan (RAT). The infection chain was observed staging a portable Java runtime and launching a malicious JAR (jd-gui.jar), while using PowerShell and living-off-the-land binaries such as cmstp.exe to reduce detection. The activity includes defense evasion by deleting the initial downloader and adding Microsoft Defender exclusions, and persistence via a scheduled task and a startup script named world.vbs; the RAT then beacons to 79.110.49[.]15 for C2, enabling data theft and follow-on payload delivery.

Reporting also noted the campaign’s use of gaming-adjacent filenames to increase execution likelihood (e.g., Xeno.exe, RobloxPlayerBeta.exe) and emphasized that the final payload functions as a loader/runner/downloader/RAT rather than a single-purpose stealer, increasing the risk of secondary malware deployment. Separately, one report highlighted the emergence of Steaelite, a Windows RAT advertised on criminal forums with claimed “FUD” capabilities and an integrated panel combining data theft and ransomware features, underscoring broader commoditization of multi-function RAT ecosystems even when not directly tied to the specific trojanized-gaming-tools intrusion chain.

Share:
Trojanized Gaming Utilities Deliver Java-Based RAT via Browser and Chat Platforms
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 27, 20264mo ago

Microsoft publishes IOCs and mitigation guidance for the campaign

Alongside its disclosure, Microsoft released indicators of compromise tied to infrastructure including 79.110.49[.]15 and powercat[.]dog, and recommended actions such as auditing Defender exclusions, checking scheduled tasks and startup scripts, isolating affected endpoints, and resetting credentials.

Microsoft identifies active trojanized gaming utility campaign

Microsoft Threat Intelligence reported an active campaign distributing trojanized gaming utilities such as Xeno.exe and RobloxPlayerBeta.exe via browsers and chat platforms. The malware chain used a downloader, portable Java runtime, a malicious JAR, PowerShell, and cmstp.exe to deploy a multi-purpose RAT capable of data theft and additional payload delivery.

Nov 1, 20258mo ago

Steaelite RAT advertised on criminal forums

BlackFog reported that the Windows RAT family Steaelite was advertised on criminal forums in November 2025 as "fully undetectable," with capabilities spanning data theft, ransomware, Defender tampering, and multiple persistence options.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Affected products
3 linked
WindowsPowershellMicrosoft Defender For Endpoint
Organizations
7 linked
Microsoft CorporationHackReadRobloxBlackFogMeta PlatformsSecurity AffairsCtrl-Alt-Intel
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.