11 Malicious NuGet Packages Pose as Game Cheats to Deploy Windows Surveillance Malware
ID: a194bfd5-7dc6-5400-b250-a59c7482a4bb
STIX ID: report--a194bfd5-7dc6-5400-b250-a59c7482a4bb
Feed Name: Cyber Press
Socket’s Threat Research Team identified 11 malicious NuGet DotnetTool packages masquerading as game cheats and panels that install a two-stage Windows surveillance payload (pepesoft.exe). The downloader (bundled as a .NET tool) retrieves a PyInstaller-packed second stage that fingerprints devices, enforces remote HWID bans, reports status and licensing to operator-controlled Google Sheets, and in some builds captures and exfiltrates screenshots via a Telegram bot; packages targeted multiple online game communities and were reported to NuGet for removal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
