Beware of Malicious Steam Cleanup Tool Attack Windows Machines to Deploy Backdoor Malware
ID: 2ff9b039-944f-522b-87da-26438b9352a2
STIX ID: report--2ff9b039-944f-522b-87da-26438b9352a2
Feed Name: cybersecurityNews.com
A sophisticated backdoor campaign abuses a trojanized version of the open-source SteamCleaner utility to deliver Node.js-based persistent backdoors on Windows. The signed Setup.exe installs components under Program Files and staged scripts in C:\WCM{UUID}\ and C:\WindowsSetting{UUID}\, registers scheduled tasks for persistence, performs anti-sandbox checks, installs Node.js via encrypted PowerShell, and establishes bidirectional JSON-based C2 communication with multiple domains (e.g., rt-guard.com, 4tressx.com, kuchiku.digital, screenner.com, aginscore.com).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
