Threat actors go gaming: Electron-based stealers in disguise
ID: d422d37a-4777-5fb3-bc20-26b4767ffbb3
STIX ID: report--d422d37a-4777-5fb3-bc20-26b4767ffbb3
Feed Name: TRU Security by Acronis
Acronis TRU uncovered active malware campaigns using Electron-based infostealers (Leet Stealer, RMC Stealer, Sniffer Stealer) disguised as fake indie-game installers promoted via fraudulent websites, YouTube channels and Discord; the stealers harvest browser credentials, Discord tokens and other sensitive data, use sandbox-detection and obfuscation techniques, and exfiltrate data via public file-hosting services. The report includes a detailed technical breakdown (including recovered unobfuscated source for RMC Stealer), campaign distribution observations (notably Portuguese-language sites and submissions from Brazil and the U.S.), and a comprehensive set of IOCs (filenames and SHA256 hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
