logo

Threat actors go gaming: Electron-based stealers in disguise

ID: d422d37a-4777-5fb3-bc20-26b4767ffbb3

STIX ID: report--d422d37a-4777-5fb3-bc20-26b4767ffbb3

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2025-07-23

Date Updated: 2026-07-24

...
...

Acronis TRU uncovered active malware campaigns using Electron-based infostealers (Leet Stealer, RMC Stealer, Sniffer Stealer) disguised as fake indie-game installers promoted via fraudulent websites, YouTube channels and Discord; the stealers harvest browser credentials, Discord tokens and other sensitive data, use sandbox-detection and obfuscation techniques, and exfiltrate data via public file-hosting services. The report includes a detailed technical breakdown (including recovered unobfuscated source for RMC Stealer), campaign distribution observations (notably Portuguese-language sites and submissions from Brazil and the U.S.), and a comprehensive set of IOCs (filenames and SHA256 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.