WebRAT Malware Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 24, 2025
Last Seen
December 24, 2025

WebRAT Malware Campaign is a threat campaign that distributes a Remote Access Trojan named WebRAT.

Overview

WebRAT Malware Campaign is a threat campaign that distributes a Remote Access Trojan named WebRAT. It uniquely leverages GitHub-hosted proof-of-concept repositories as the delivery vector, using a trusted development platform to host or reference malicious payloads. This approach increases stealth and poses elevated risk to developers and GitHub users by turning a legitimate resource into a malware distribution channel.

Related Threat Clusters

  • WebRAT Malware Campaign Exploits GitHub for Distribution

    Kaspersky has identified 15 malicious GitHub repositories spreading WebRAT malware disguised as proof-of-concept exploits. Some of these exploits are reportedly crafted with generative AI technology, and victims receive…

    2 articles · Updated December 24, 2025

Recent Intelligence Reports

  • WebRAT Malware Campaign Leveraging GitHub-Hosted Proof-of — Gbhackers · December 24, 2025

Related Entities

CVSS v3.1 Breakdown