New RAT Poses as Minecraft Nursultan Client
Researchers find a new RAT disguised as Nursultan, a Minecraft app. It exploits Telegram for command-and-control, affecting all major OS platforms.
A new Python-based remote-access trojan (RAT) masquerading as the 'Nursultan Client,' a Minecraft application, has been discovered in Eastern Europe. This malware employs the Telegram Bot API for command-and-control operations, impacting Windows, Linux, and macOS environments.
Key facts
- Netskope identified the RAT targeting Windows, Linux, and macOS as of 2025-10-23.
- The malware mimics Nursultan, a Minecraft client popular in Eastern Europe.
- Exfiltration via Telegram Bot API includes system details and user data.
- The RAT's persistence is flawed due to incorrect path handling.
- Netskope classifies this threat as QD:Trojan.GenericKDQ.F8A018F2A0.
Impact / What’s next
Though the RAT leverages several standard functionalities like system reconnaissance and Discord token theft, its persistence issues mean it fails to remain active post-reboot. Its reliance on open-source components suggests a moderate threat level with a potential link to a growing Malware-as-a-Service model.
Users and organizations are advised to monitor for illicit encrypted communications over Telegram, often used by the malware to blend its traffic. Enhanced threat detection and scrutiny of seemingly legitimate traffic are crucial to mitigate this risk.