Webrat, disguised as exploits, is spreading via GitHub repositories
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10294 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to log in as other users, including administrators, on instances where the plugin has not been fully configured yet. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-11499 | The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image_from_external_url() function in all versions up to, and including, 1.1.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible in configurations where unauthenticated users have been provided with a method for adding featured images, and the workflow trigger is created. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-11833 | Unauthenticated Email-Log Access in Post SMTP WordPress Plugin (<= 3.6.0) CVE-2025-11833 is a missing-authorization flaw (CWE-862) in the Post SMTP WordPress plugin: in all versions up to and including 3.6.0, the email-log handling set up in the plugin's __construct function is registered without a capability check, so the log-viewing functionality effectively accepts requests from anyone. Any unauthenticated visitor who can reach the site can therefore read arbitrary emails logged by Post SMTP, including WordPress password-reset emails containing password reset links. By harvesting a reset link addressed to an administrator, an attacker can complete the password reset and take over the account, a full site-admin compromise reflected in the critical 9.8 CVSS score. Any WordPress site running Post SMTP 3.6.0 or earlier is affected, on the order of hundreds of thousands of installations. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is documented yet, but the EPSS of 51% (99th percentile) signals a high probability of exploitation within the next 30 days. Do: Update the Post SMTP plugin to the latest release, since every version through 3.6.0 is vulnerable. Until patched, purge stored email logs, consider temporarily disabling the plugin or blocking its log endpoints with WAF rules, and review the log for password-reset emails sent to administrators; treat any admin account whose reset emails appear in the log as potentially compromised, rotate those credentials, and enable two-factor authentication. | 9.8 | 51% |
| mass≈300,000+ sites (Post SMTP has roughly 300k active installs on WordPress.org) | ||
| CVE-2025-12596 +1 in the same advisory: …12595 | A security vulnerability has been detected in Tenda AC23 16.03.07.52. A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of the file /goform/saveParentControlInfo. Such manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. NVD description · AI analysis pending | 7.4 | 1% | PoC |
| — | |
| CVE-2025-54106 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2025-54897 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 19% |
| — | ||
| CVE-2025-55234 | SMB Relay Elevation of Privilege in Microsoft Windows SMB Server CVE-2025-55234 is an improper authentication flaw (CWE-287) in the Microsoft SMB Server that leaves systems susceptible to credential relay attacks when SMB signing and Extended Protection for Authentication (EPA) are not enforced. It is configuration-dependent: an attacker who can induce an authenticated SMB connection, for example by tricking a user or machine into connecting to attacker-controlled resources, can relay the credentials to another host and authenticate as that user. Successful relaying grants the attacker the privileges of the relayed user, up to elevation of privilege on target systems, with high impact on confidentiality, integrity and availability. Affected systems span Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), and Windows Server 2008, 2012, 2016 and 2019, although only environments without SMB signing/EPA hardening are practically exploitable. As of the September 2025 Patch Tuesday release there is no known in-the-wild exploitation or public proof of concept, but EPSS assigns a 20.1% probability of exploitation within the next 30 days (97th percentile). Do: Install the September 2025 (or later) Microsoft security updates, which add SMB Server Hardening audit capabilities, and use the new audit events to identify clients, servers or legacy software that would break if SMB signing and EPA are enforced. After remediating incompatibilities, enable SMB Server signing and Extended Protection for Authentication on SMB servers to close the relay exposure, prioritizing domain controllers and file servers. Note that systems already enforcing both signing and EPA are not practically exposed. | 9.8 | 20% |
| masshundreds of millions of Windows 10/11 devices plus millions of Windows Server instances are potentially exposed, though only those lacking SMB signing/EPA… | ||
| CVE-2025-59230 | Local Privilege Escalation in Windows Remote Access Connection Manager (RasMan) CVE-2025-59230 is an improper access control flaw (CWE-284) in the Windows Remote Access Connection Manager service that allows an attacker who already has low-privileged access on a machine to gain elevated privileges locally. It is triggered by a local, authenticated user abusing the flawed access checks in the service; no remote or unauthenticated attack path is indicated by the CVSS vector (AV:L/PR:L). A successful exploit yields high impact to confidentiality, integrity and availability on the host, effectively giving the attacker full local control that can support persistence and lateral movement. All listed Windows 10 and Windows 11 releases and Windows Server 2008, 2012 and 2016 are affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-14, coinciding with Microsoft's October 2025 Patch Tuesday (one of six actively exploited zero-days patched that day), though no public PoC is known and ransomware use is unknown. Do: Apply Microsoft's October 2025 security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing the per-version updates listed in Microsoft's advisory; as a CISA KEV entry (added 2025-10-14), BOD 22-01 remediation timelines apply for federal agencies. Because exploitation requires local code execution, prioritize hosts where low-privileged users can run code (RDS/VDI servers, kiosks, shared workstations) and verify that clients and servers have pulled the latest cumulative updates rather than relying on HEU state. There is no public PoC or documented mitigation, so patching is the primary defense. | 7.8 | 3% | KEV |
| masshundreds of millions of Windows endpoints and millions of Windows Servers (the listed versions cover essentially the entire supported Windows desktop and… | |
| CVE-2025-59295 | Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 2% |
| — |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | ezc5510min.temp.swtest.ru | hub[.]com/lagerhaker539/CVE-2025-12595-POC Webrat C2 http://ezc5510min[.]temp[.]swtest[.]ru http://shopsleta[.]ru MD5 28a741e9fcd57bd607255d3a469 |
| domain | github.com | icators of compromise Malicious GitHub repositories https://github[.]com/RedFoxNxploits/CVE-2025-10294-Poc https://github[.]com/Fi |
| domain | shopsleta.ru | POC Webrat C2 http://ezc5510min[.]temp[.]swtest[.]ru http://shopsleta[.]ru MD5 28a741e9fcd57bd607255d3a4690c82f a13c3d863e8e2bd7596b |
| domain | temp.swtest.ru | to avoid detection. Fetch from a hardcoded URL (ezc5510min.temp[.]swtest[.]ru in our example) a sample of the Webrat family and execu |
| md5 | 28a741e9fcd57bd607255d3a4690c82f | //ezc5510min[.]temp[.]swtest[.]ru http://shopsleta[.]ru MD5 28a741e9fcd57bd607255d3a4690c82f a13c3d863e8e2bd7596bac5d41581f6a 61b1fc6ab327e6d3ff5fd3e82b |
| md5 | 61b1fc6ab327e6d3ff5fd3e82b430315 | note: file names may vary): the primary malicious file (MD5 61b1fc6ab327e6d3ff5fd3e82b430315), which performs the following actions: Escalate its privil |
| md5 | a13c3d863e8e2bd7596bac5d41581f6a | http://shopsleta[.]ru MD5 28a741e9fcd57bd607255d3a4690c82f a13c3d863e8e2bd7596bac5d41581f6a 61b1fc6ab327e6d3ff5fd3e82b430315 |
Full article824 words · extracted from securelist.com · click to collapse
In early 2025, security researchers uncovered a new malware family named Webrat. Initially, the Trojan targeted regular users by disguising itself as cheats for popular games like Rust, Counter-Strike, and Roblox, or as cracked software. In September, the attackers decided to widen their net: alongside gamers and users of pirated software, they are now targeting inexperienced professionals and students in the information security field.
Distribution and the malicious sample
In October, we uncovered a campaign that had been distributing Webrat via GitHub repositories since at least September. To lure in victims, the attackers leveraged vulnerabilities frequently mentioned in security advisories and industry news. Specifically, they disguised their malware as exploits for the following vulnerabilities with high CVSSv3 scores:
| CVE | CVSSv3 |
| CVE-2025-59295 | 8.8 |
| CVE-2025-10294 | 9.8 |
| CVE-2025-59230 | 7.8 |
This is not the first time threat actors have tried to lure security researchers with exploits. Last year, they similarly took advantage of the high-profile RegreSSHion vulnerability, which lacked a working PoC at the time.
In the Webrat campaign, the attackers bait their traps with both vulnerabilities lacking a working exploit and those which already have one. To build trust, they carefully prepared the repositories, incorporating detailed vulnerability information into the descriptions. The information is presented in the form of structured sections, which include:
- Overview with general information about the vulnerability and its potential consequences
- Specifications of systems susceptible to the exploit
- Guide for downloading and installing the exploit
- Guide for using the exploit
- Steps to mitigate the risks associated with the vulnerability
Contents of the repository
In all the repositories we investigated, the descriptions share a similar structure, characteristic of AI-generated vulnerability reports, and offer nearly identical risk mitigation advice, with only minor variations in wording. This strongly suggests that the text was machine-generated.
The Download Exploit ZIP link in the Download & Install section leads to a password-protected archive hosted in the same repository. The password is hidden within the name of a file inside the archive.
The archive downloaded from the repository includes four files:
- pass – 8511: an empty file, whose name contains the password for the archive.
- payload.dll: a decoy, which is a corrupted PE file. It contains no useful information and performs no actions, serving only to divert attention from the primary malicious file.
- rasmanesc.exe (note: file names may vary): the primary malicious file (MD5 61b1fc6ab327e6d3ff5fd3e82b430315), which performs the following actions:
- Escalate its privileges to the administrator level (T1134.002).
- Disable Windows Defender (T1562.001) to avoid detection.
- Fetch from a hardcoded URL (ezc5510min.temp[.]swtest[.]ru in our example) a sample of the Webrat family and execute it (T1608.001).
- start_exp.bat: a file containing a single command: start rasmanesc.exe, which further increases the likelihood of the user executing the primary malicious file.
The execution flow and capabilities of rasmanesc.exe
Webrat is a backdoor that allows the attackers to control the infected system. Furthermore, it can steal data from cryptocurrency wallets, Telegram, Discord and Steam accounts, while also performing spyware functions such as screen recording, surveillance via a webcam and microphone, and keylogging. The version of Webrat discovered in this campaign is no different from those documented previously.
Campaign objectives
Previously, Webrat spread alongside game cheats, software cracks, and patches for legitimate applications. In this campaign, however, the Trojan disguises itself as exploits and PoCs. This suggests that the threat actor is attempting to infect information security specialists and other users interested in this topic. It bears mentioning that any competent security professional analyzes exploits and other malware within a controlled, isolated environment, which has no access to sensitive data, physical webcams, or microphones. Furthermore, an experienced researcher would easily recognize Webrat, as it’s well-documented and the current version is no different from previous ones. Therefore, we believe the bait is aimed at students and inexperienced security professionals.
Conclusion
The threat actor behind Webrat is now disguising the backdoor not only as game cheats and cracked software, but also as exploits and PoCs. This indicates they are targeting researchers who frequently rely on open sources to find and analyze code related to new vulnerabilities.
However, Webrat itself has not changed significantly from past campaigns. These attacks clearly target users who would run the “exploit” directly on their machines — bypassing basic safety protocols. This serves as a reminder that cybersecurity professionals, especially inexperienced researchers and students, must remain vigilant when handling exploits and any potentially malicious files. To prevent potential damage to work and personal devices containing sensitive information, we recommend analyzing these exploits and files within isolated environments like virtual machines or sandboxes.
We also recommend exercising general caution when working with code from open sources, always using reliable security solutions, and never adding software to exclusions without a justified reason.
Kaspersky solutions effectively detect this threat with the following verdicts:
- HEUR:Trojan.Python.Agent.gen
- HEUR:Trojan-PSW.Win64.Agent.gen
- HEUR:Trojan-Banker.Win32.Agent.gen
- HEUR:Trojan-PSW.Win32.Coins.gen
- HEUR:Trojan-Downloader.Win32.Agent.gen
- PDM:Trojan.Win32.Generic
Indicators of compromise
Malicious GitHub repositories
https://github[.]com/RedFoxNxploits/CVE-2025-10294-Poc
https://github[.]com/FixingPhantom/CVE-2025-10294
https://github[.]com/h4xnz/CVE-2025-10294-POC
https://github[.]com/usjnx72726w/CVE-2025-59295/tree/main
https://github[.]com/stalker110119/CVE-2025-59230/tree/main
https://github[.]com/moegameka/CVE-2025-59230
https://github[.]com/DebugFrag/CVE-2025-12596-Exploit
https://github[.]com/themaxlpalfaboy/CVE-2025-54897-LAB
https://github[.]com/DExplo1ted/CVE-2025-54106-POC
https://github[.]com/h4xnz/CVE-2025-55234-POC
https://github[.]com/Hazelooks/CVE-2025-11499-Exploit
https://github[.]com/usjnx72726w/CVE-2025-11499-LAB
https://github[.]com/modhopmarrow1973/CVE-2025-11833-LAB
https://github[.]com/rootreapers/CVE-2025-11499
https://github[.]com/lagerhaker539/CVE-2025-12595-POC
Webrat C2
http://ezc5510min[.]temp[.]swtest[.]ru
http://shopsleta[.]ru
MD5
28a741e9fcd57bd607255d3a4690c82f
a13c3d863e8e2bd7596bac5d41581f6a
61b1fc6ab327e6d3ff5fd3e82b430315
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/webrat-distributed-via-github/118555/