Netskope researchers exposed a Telegram-controlled trojan disguised as the Nursultan Client that screenshots your screen, activates your webcam, and lifts Discord tokens after you run the fake installer.

Minecraft players chasing custom clients just got another reason to stop. Netskope threat researchers have broken down a new Python RAT that wraps itself in the name of Nursultan Client, a real but unofficial Minecraft client used by some Eastern European and Russian players. The fake version is not harmless software. It is a multi-function backdoor that phones home over Telegram and gives attackers remote control.
What The Malware Actually Does
- Takes screenshots on command
- Activates the webcam to snap photos of the victim
- Steals Discord authentication tokens from local storage
- Opens arbitrary URLs in the browser to push more payloads
- Performs system reconnaissance and sets up persistence via registry keys
The attack leans hard on social engineering. Victims are lured with promises of a free or cracked version of a known client. Once executed, the malware pretends to install normally while quietly registering itself under the Nursultan name to blend in. It then waits for commands from a Telegram bot controlled by the operator. Netskope notes signs this could be sold as malware-as-a-service, letting other criminals rent access to the same tool.

This campaign is part of a persistent pattern. Threat actors have repeatedly poisoned search results and file hosts to push infected Minecraft tools. The Telegram C2 makes it cheap and flexible for the attackers while giving them plausible separation from the actual victims. Persistence is not perfect, but it is good enough to survive most casual restarts.
If you think you might have run something suspicious, check for unusual Telegram-related processes, unknown registry entries under Run keys, and unexpected Discord logins from new devices. Better yet, avoid the entire category of third-party clients entirely. The real game does not need them.