Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets
ID: cbbcaf94-685b-5b69-b217-8148acbc272a
STIX ID: report--cbbcaf94-685b-5b69-b217-8148acbc272a
Feed Name: cybersecurityNews.com
Criminals are luring victims with fake game downloads, mods, and cracks that install a multi-stage loader (RenPy Loader) which ultimately deploys Amatera Stealer to exfiltrate browser credentials, session cookies, cryptocurrency wallets, messaging data, and local files. The chain abuses legitimate tools (forfiles.exe, MSBuild) and uses techniques like EtherHiding (retrieving C2 from blockchain data) to complicate takedowns; the report includes domains, IPs, and MD5 hashes as IoCs and recommends restricting unapproved software, monitoring unusual MSBuild/forfiles/Setup.exe activity, and preserving suspicious artifacts for analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
