π¨ New malware analysis: Trojanized Solara/Yuta loader abusing LLM functionality π€β οΈ
The .NET app masquerades as a Roblox utility while integrating DeepSeek to generate Roblox Luau exploit scripts. Its hardcoded prompt steers the model toward exploit-oriented primitives such as hookmetamethod(), hookfunction(), getgenv(), gethui(), and remote invocation.
It also includes an "AI reconstructor" feature that feeds Roblox script sources into the LLM to clean, rename, comment, reconstruct, and deobfuscate code while preserving functionality. π§©
But the AI features are only part of the story: behind the UI, the app silently retrieves a second-stage Python stealer/RAT via Pastebin β MediaFire. π₯
The payload includes credential theft, Discord/Telegram C2, persistence, keylogging, screenshot capture, AMSI/ETW patching, and Defender evasion.
buff.ly/8WbOPMp
Verdict: Malicious β 10/10 π₯