BleepingComputer reports that over a dozen GitHub repositories purporting to have proof-of-concept exploits for several newly disclosed flaws including the Windows Remote Access Connection Manager privilege escalation bug, tracked as CVE-2025-59230 have been leveraged to distribute the WebRAT malware since September.
All of the malicious GitHub repositories, which have since been removed, contained vulnerability descriptions and deployed the bogus exploits through a password-protected ZIP file and an empty file whose name is the password, a corrupted decoy DLL, and a batch file, as well as the rasmanesc.exe dropper, according to an analysis from Kaspersky.
After enabling privilege escalation and deactivating Windows Defender, the dropper runs WebRAT, which was previously reported by Solar 4RAYS researchers to have the ability to not only pilfer Steam, Telegram, and Discord credentials, and cryptocurrency wallet information, but also facilitate screenshot capturing and webcam hijacking.
Such a development comes after information-stealing malware was noted to have been distributed using a counterfeit LDAPNightmare exploit on GitHub.
All of the malicious GitHub repositories, which have since been removed, contained vulnerability descriptions and deployed the bogus exploits through a password-protected ZIP file and an empty file whose name is the password, a corrupted decoy DLL, and a batch file, as well as the rasmanesc.exe dropper, according to an analysis from Kaspersky.
After enabling privilege escalation and deactivating Windows Defender, the dropper runs WebRAT, which was previously reported by Solar 4RAYS researchers to have the ability to not only pilfer Steam, Telegram, and Discord credentials, and cryptocurrency wallet information, but also facilitate screenshot capturing and webcam hijacking.
Such a development comes after information-stealing malware was noted to have been distributed using a counterfeit LDAPNightmare exploit on GitHub.
