Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantinitial-access-methodsearch-ad-manipulationoffensive-tooling-release

GitHub Gaming Cheat Projects Used to Deliver AsyncRAT and VileRAT Malware

Updated 9d agoFirst seen Nov 14, 20232 sources

Security researchers and sandbox telemetry identified malware campaigns abusing GitHub-hosted gaming cheat projects to distribute remote access trojans, including AsyncRAT and VileRAT. One analyzed sample was delivered from a GitHub raw URL and disguised as an Escape from Tarkov cheat-related .scr file, using a gaming-themed lure to entice users seeking cheats, DLL injectors, or other unauthorized tools. ANY.RUN classified the sample as malicious and linked it to AsyncRAT, a trojan that can provide remote control, keystroke capture, webcam access, and data theft from infected Windows systems.

Additional reporting warned that attackers were packaging malware inside purported open-source game cheat repositories and injector utilities on GitHub, broadening the campaign beyond a single title or payload. Technical analysis tied related activity to VileRAT, indicating that threat actors are using trusted developer platforms and cheat-seeking communities as an infection channel for commodity and custom RAT malware. Reported indicators for the AsyncRAT sample included SHA1 3065DA0D35988807C34C98164D35385F846AB1DF and SHA256 84C8AD42D82A82951A1968C738FC813A83FC5CD6F1C2F446F2960CF21A373E14.

Share:
GitHub Gaming Cheat Projects Used to Deliver AsyncRAT and VileRAT Malware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

1 event from the most recent confirmed update back to the earliest known activity.

1 EVENTS
Nov 14, 20233y ago

ANY.RUN analyzes GitHub-hosted AsyncRAT gaming lure sample

ANY.RUN conducted a sandbox analysis of a malicious Windows sample hosted at a GitHub raw URL and identified it as AsyncRAT. The file masqueraded as an Escape from Tarkov cheat-related executable or screensaver, indicating a gaming-themed social-engineering lure.

Malware analysis https://github.com/supoyev/Escape-from-Tarkov-External-Esp-Aimbot-Cheat/raw/main/escape%20from%20tarkov/Escape%20From%20Tarkov/Escape%20From%20Tarkov%E2%80%AEnls..scr Malicious activity | ANY.RUN - Malware Sandbox Online
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
Malware
1 linked
Affected products
11 linked
CcleanerVlc Media PlayerEdge UpdateAcrobat Reader DcFirefoxFlash PlayerNotepad++EdgeWinrarSkypeChrome
Organizations
12 linked
MozillaNotepad++VideolanAvastWinRARMicrosoft CorporationGitHubAdobeAny.RunOracleSkypeGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.