logo

Threat actors go gaming: Electron-based stealers in disguise

ID: 8f6ea424-c477-591e-83d9-5d21a0e24207

STIX ID: report--8f6ea424-c477-591e-83d9-5d21a0e24207

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2025-07-18

Date Updated: 2026-07-24

...
...

Acronis TRU uncovered an active campaign distributing Electron-based infostealers (Leet, RMC, Sniffer) disguised as fake indie game installers promoted via Discord, fake websites and YouTube channels; the report includes technical analysis (unobfuscated source in one sample), sandbox-evasion, browser and Discord token exfiltration, and extensive IoCs (SHA256s and malicious URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.