South Korea’s Internet cafés, known locally as “PC bangs,” have become the latest battleground for cybercriminals, with a sophisticated campaign leveraging Gh0st RAT and crypto-mining malware to exploit these environments.
According to recent intelligence from AhnLab Security Intelligence Center (ASEC) Report, a threat actor active since 2022 has systematically targeted computers running Internet café management software since the latter half of 2024.
These attacks aim to covertly seize control of the systems and install the T-Rex CoinMiner to generate illicit revenue through cryptocurrency mining.
Korean Internet Cafés
Internet cafés across Korea rely on dedicated management programs to track customer sessions, calculate usage fees, and automate administrative tasks.

The attackers appear to have thoroughly analyzed these programs, gaining a precise understanding of their operation and deployment.
Although the exact method of initial access remains under investigation, indicators suggest that compromised management software is the primary vector, with most attacks focusing on systems where such tools are installed.
Once a target system is compromised, the attackers deploy Gh0st RAT a notorious remote administration tool originally developed by the Chinese C.
Rufus Security Team and widely adopted among threat actors, especially those in Chinese-speaking regions.
Gh0st RAT’s open-source nature and modularity allow attackers to maintain persistent control over infected hosts, enabling a spectrum of malicious operations such as process and file manipulation, keylogging, and screen capture.
In these incidents, Gh0st RAT communicates with its command-and-control (C&C) servers using the custom identifier “Level” to evade common detection signatures.
Exploit High-Performance Gaming PCs
A distinctive tactic of this campaign involves the use of auxiliary malware dubbed “Patcher.”
This component scans running processes for the management program, reads memory patterns, and then patches program memory to facilitate further malware deployment and maintain foothold.
The presence of logs indicating the installation of Gh0st RAT droppers in related folder paths further suggests that attackers engineered persistence mechanisms tailored specifically for the Internet café software environment.

The ultimate payload in this operation is the T-Rex CoinMiner, favored over the more ubiquitous XMRig miner for its optimized use of GPUs a common feature in gaming-centric café setups.
By harnessing the powerful graphics hardware in these PCs, the T-Rex miner targets cryptocurrencies like Ethereum and RavenCoin.
The malware is typically concealed within system folders and masquerades as legitimate executables, with installation paths shifting in response to software updates to evade detection.
Supporting malware such as custom downloaders distribute additional payloads, including other miners, droppers, and process-killing utilities (“KillProc”) designed to eliminate competing cryptomining processes or circumvent software used to block illicit activities.
The attackers’ flexibility in tool use is reflected in found samples of PhoenixMiner and other mining tools, highlighting their singular focus on maximizing unlawful mining profits.
Administrators of Internet cafés are strongly advised to prioritize timely updates to both operating systems and management software, maintain current threat protection solutions, and monitor for known indicators of compromise (IoCs).
Regular audits and process whitelisting can further fortify defenses against these evolving threats.
Indicators of Compromise (IoC)
| Type | Value |
|---|---|
| MD5 | 04840bb2f22c28e996e049515215a744 |
| 0b05b01097eec1c2d7cb02f70b546fff | |
| 142b976d89400a97f6d037d834edfaaf | |
| 15ba916a57487b9c5ceb8c76335b59b7 | |
| 15d6f2a36a4cd40c9205e111a7351643 | |
| URL | http[:]//112[.]217[.]151[.]10/config[.]txt |
| http[:]//112[.]217[.]151[.]10/mm[.]exe | |
| http[:]//112[.]217[.]151[.]10/pms[.]exe | |
| http[:]//112[.]217[.]151[.]10/statx[.]exe | |
| http[:]//121[.]67[.]87[.]250/3[.]exe | |
| IP | 103[.]25[.]19[.]32 |
| 113[.]21[.]17[.]102 | |
| 115[.]23[.]126[.]178 | |
| 121[.]147[.]158[.]132 | |
| 122[.]199[.]149[.]129 |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.