Hackers Exploiting Fake Battlefield 6 Popularity to Deploy Stealers and C2 Agents
ID: b1d9a477-8433-5f43-83f7-925cb8b21498
STIX ID: report--b1d9a477-8433-5f43-83f7-925cb8b21498
Feed Name: cybersecurityNews.com
Researchers observed multiple malware campaigns impersonating game-cracking groups to distribute fake Battlefield 6 trainers and ISOs via torrents and search results; three malware families were identified: an information stealer exfiltrating browser sessions and crypto wallet data to 198.251.84.9, a more advanced variant with Windows API hashing, anti-sandbox checks and regional execution blocking, and a persistent C2-enabled agent that installs a DLL which contacts Google-related infrastructure and supports remote commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
