Cyber Criminals Infiltrate Internet Cafés with Gh0st RAT to Mine Crypto

South Korea’s Internet cafés, known locally as “PC bangs,” have become the latest battleground for cybercriminals, with a sophisticated campaign leveraging Gh0st RAT and crypto-mining malware to exploit these environments.

According to recent intelligence from AhnLab Security Intelligence Center (ASEC) Report, a threat actor active since 2022 has systematically targeted computers running Internet café management software since the latter half of 2024.

These attacks aim to covertly seize control of the systems and install the T-Rex CoinMiner to generate illicit revenue through cryptocurrency mining.

Korean Internet Cafés

Internet cafés across Korea rely on dedicated management programs to track customer sessions, calculate usage fees, and automate administrative tasks.

 Gh0st RAT
Flowchart

The attackers appear to have thoroughly analyzed these programs, gaining a precise understanding of their operation and deployment.

Although the exact method of initial access remains under investigation, indicators suggest that compromised management software is the primary vector, with most attacks focusing on systems where such tools are installed.

Once a target system is compromised, the attackers deploy Gh0st RAT a notorious remote administration tool originally developed by the Chinese C.

Rufus Security Team and widely adopted among threat actors, especially those in Chinese-speaking regions.

Gh0st RAT’s open-source nature and modularity allow attackers to maintain persistent control over infected hosts, enabling a spectrum of malicious operations such as process and file manipulation, keylogging, and screen capture.

In these incidents, Gh0st RAT communicates with its command-and-control (C&C) servers using the custom identifier “Level” to evade common detection signatures.

Exploit High-Performance Gaming PCs

A distinctive tactic of this campaign involves the use of auxiliary malware dubbed “Patcher.”

This component scans running processes for the management program, reads memory patterns, and then patches program memory to facilitate further malware deployment and maintain foothold.

The presence of logs indicating the installation of Gh0st RAT droppers in related folder paths further suggests that attackers engineered persistence mechanisms tailored specifically for the Internet café software environment.

 Gh0st RAT
Gh0st RAT in the resource

The ultimate payload in this operation is the T-Rex CoinMiner, favored over the more ubiquitous XMRig miner for its optimized use of GPUs a common feature in gaming-centric café setups.

By harnessing the powerful graphics hardware in these PCs, the T-Rex miner targets cryptocurrencies like Ethereum and RavenCoin.

The malware is typically concealed within system folders and masquerades as legitimate executables, with installation paths shifting in response to software updates to evade detection.

Supporting malware such as custom downloaders distribute additional payloads, including other miners, droppers, and process-killing utilities (“KillProc”) designed to eliminate competing cryptomining processes or circumvent software used to block illicit activities.

The attackers’ flexibility in tool use is reflected in found samples of PhoenixMiner and other mining tools, highlighting their singular focus on maximizing unlawful mining profits.

Administrators of Internet cafés are strongly advised to prioritize timely updates to both operating systems and management software, maintain current threat protection solutions, and monitor for known indicators of compromise (IoCs).

Regular audits and process whitelisting can further fortify defenses against these evolving threats.

Indicators of Compromise (IoC)

TypeValue
MD504840bb2f22c28e996e049515215a744
0b05b01097eec1c2d7cb02f70b546fff
142b976d89400a97f6d037d834edfaaf
15ba916a57487b9c5ceb8c76335b59b7
15d6f2a36a4cd40c9205e111a7351643
URLhttp[:]//112[.]217[.]151[.]10/config[.]txt
http[:]//112[.]217[.]151[.]10/mm[.]exe
http[:]//112[.]217[.]151[.]10/pms[.]exe
http[:]//112[.]217[.]151[.]10/statx[.]exe
http[:]//121[.]67[.]87[.]250/3[.]exe
IP103[.]25[.]19[.]32
113[.]21[.]17[.]102
115[.]23[.]126[.]178
121[.]147[.]158[.]132
122[.]199[.]149[.]129

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories