New Python RAT Targets Minecraft With Nursultan Client Disguise

A Python RAT disguises as Nursultan Client for Minecraft, using Telegram for remote control, posing risks to users.

M
minecraftnew.com
24 Oct 2025

A new Python-based remote access trojan (RAT) has been targeting Minecraft players, masquerading as a reliable game client to steal sensitive data. Named the Python RAT, it emerges under the guise of the 'Nursultan Client', popular among Eastern-European and Russian users, making it particularly deceiving.

Key facts

  • Netskope researchers identified the RAT on 2025-10-24, masquerading as a Minecraft client.
  • The malware uses the Telegram Bot API for command and control, exfiltrating data from user systems.
  • Packed using PyInstaller, its executable is 68.5 MB, larger than typical files, to avoid size-based detection.
  • The threat targets Discord tokens and browser-stored data across various platforms like Chrome, Edge, and Firefox.
  • It attempts to maintain persistence in Windows but faces obstacles due to flawed startup mechanism coding.

Capabilities & impact

The RAT's functionality extends beyond disguise, incorporating extensive surveillance and data theft tools such as Discord token extraction and webcam access. It captures detailed system reconnaissance and user information. Mainly posing threats to gamers through unofficial clients, it is indicative of a Malware-as-a-Service operation where various operators can control infected systems remotely and independently, emphasizing the need for vigilance when downloading game mods or clients.