“Can you try a game I made?” Fake Game Sites Lead to Information Stealers
ID: 082d3fe2-b433-5290-b8f1-68e97731c95e
STIX ID: report--082d3fe2-b433-5290-b8f1-68e97731c95e
Feed Name: infostealers.com
Malwarebytes reports an active campaign where attackers lure victims with fake videogame beta invites (via Discord DMs, SMS, or email) and host passworded archives on services like Discord CDN, Dropbox, Catbox, and Blogspot. The downloaded installers (NSIS/MSI) deliver information-stealing trojans — notably Nova Stealer, Ageo Stealer, and Hexon — that exfiltrate Discord tokens, browser credentials/cookies, autofill data, credit card details, 2FA backup codes, and cryptocurrency wallet data; the report includes example templated fake sites and a list of known malicious download domains and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
