Group-IB observed malicious packages masquerading as, or trojanizing, tools sought by other cybercriminals. Examples reportedly involved names associated with XWorm, AsyncRAT, njRAT, token grabbers, and exploit builders.
The irony is clear: people searching for offensive malware or criminal tools may themselves become malware victims. A user looking to deploy AsyncRAT may download what they believe is an AsyncRAT builder and instead infect their own machine with Millenium RAT. This criminal-to-criminal targeting pattern is a documented part of the Millenium RAT distribution ecosystem.
From a defensive perspective, this means threat actors operating in offensive-tool communities are themselves a vulnerable population, and defenders should be aware that machines used to seek or test offensive tooling may be compromised by competing malware.
