The trojanized installer, identified as Kuailian_win-setup.86.msi, embeds a loader and an encrypted payload alongside the authentic LetsVPN application.
Armored Likho utilizes a modular and evolving toolkit that includes obfuscated remote access trojans (RATs), the Python-based BusySnake Stealer, and Go2Tunnel for network tunneling.
QuimaRAT features a modular architecture, allowing for dynamic expansion of capabilities through encrypted plugins delivered via its command-and-control (C2) infrastructure.
The "Google Notes" extension, identified by McAfee researchers, operates by requesting broad permissions, including access to all websites, browsing history, and the clipboard, which are unusual for a note-taking application.