Bottom Line: An in-memory RAT named GoodPersonRAT is being distributed through fake LetsVPN installer packages and requires immediate vigilance regarding the origin of VPN software.
Security analysts at ThreatLocker have uncovered a malware campaign in which manipulated installers for Kuailian VPN (LetsVPN) serve as a transport medium for the remote access trojan GoodPersonRAT. The malware operates entirely in RAM, thereby evading file-based detection methods.
Infection Mechanism and Concealment: The prepared file is named Kuailian_win-setup.86.msi and contains both the legitimate, digitally signed VPN application and the malware GoodPersonRAT as a payload. The installer initially executes the malware in the background, then launches the legitimate VPN program, thereby creating the appearance of a normal installation process. The targets are particularly users who deploy VPN software to circumvent internet censorship.
Technical Distinction – In-Memory Execution: After executing the MSI file, the malicious code functions as a multi-stage loader and directly loads the actual RAT payload into the system’s RAM. Since the payload does not touch the hard drive, it remains undetected by signature and file system-based detection methods of conventional security solutions. The malware possesses a list of 40 command-and-control servers; several domain names derive from the Chinese term “Nishihaoren” (你是好人, translated: “you are a good person”).
Persistence and Functionality: The trojan registers itself as a Windows service and via scheduled tasks with system rights to launch automatically before user logon. Its range of functions includes screen recording, clipboard exfiltration, full keyboard logging, extraction of browser data (cookies, profiles, history), theft of Telegram Desktop session data, and execution of arbitrary system commands. The malware deletes existing browser sessions and cookies to force users to re-enter login credentials, which it then captures via keylogging. Additionally, the malware disables security features of Microsoft Defender.
Distribution Channels and Implications: The exact distribution mechanisms are not fully known; however, experts suspect the use of manipulated search engine advertising or phishing links. For CISOs, it is critical that this threat specifically targets users who deliberately turn to VPN solutions. Corporate policies should exercise stricter control over software origin, verify download sources, and supplement in-memory malware detection through endpoint detection and response (EDR) systems that analyze process behavior.
Source: www.it-daily.net · Published July 14, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.