Nursultan Client Malware: Minecraft App Masks Python RAT
Netskope found 'Nursultan' malware, disguised as Minecraft app, leveraging Telegram API for data theft.
Netskope researchers have discovered a Python-based Remote Access Trojan (RAT) named 'Nursultan Client' masquerading as a Minecraft application. This malware, widely distributed in Eastern-European and Russian gaming communities, employs the Telegram Bot API for command-and-control operations.
Key facts
- The malware was uncovered on 2025-10-23 by Netskope.
- 'Nursultan Client' targets users in Eastern Europe and Russia.
- It uses a 68.5 MB executable compiled with PyInstaller.
- Core functionalities run on Windows, Linux, and other platforms.
- Telegram API facilitates its command-and-control activities.
Impact / What's next
The Trojan steals sensitive data by profiling systems and exfiltrating Discord tokens from various browsers, while its adware can open unwanted URLs. Despite its cross-platform reach, Windows-specific persistence and credential-stealing methods exist. This points to targeting by lower-tier threat actors with less advanced anti-analysis measures.
Organizations are advised to increase monitoring of encrypted traffic and to educate users on verifying software authenticity before installation. This malware's improper use of startup scripting and unencrypted command structures underscores its unsophisticated nature, but still poses significant risks to uninformed users.