• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    NJRAT launched by GTA-branded launchers from TEMP with firewall rule creation

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Adarsh Pandey@Pandeyadarsh
    •updated today•0•0•0

    Detects the execution of NJRAT or related payloads launched via fake GTA, Rockstar, or Steam game launchers residing in temporary directories, accompanied by firewall rule modifications via netsh and outbound connections to known C2 infrastructure or Ngrok tunnels.

    Splunk (SPL)

    Tags

    T1059 - Command and Scripting InterpreterT1686 - Disable or Modify System FirewallT1071 - Application Layer ProtocolS0385 - njRATTA0002 - ExecutionProcess CreationFirewall EventNetwork Connection OutboundMalware DetectedWindowsWindows SysmonWindows Advanced Firewallspl

    Found in

    • Grand Theft Auto VI Hype Leads to MalwareLast updated 28 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?