logo

Distribution of Backdoor Malware with Legitimate Signature, Disguised as Steam Cleanup Tool

ID: b1223441-3da2-501e-be9d-c03b14f0e34d

STIX ID: report--b1223441-3da2-501e-be9d-c03b14f0e34d

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-11-09

Date Updated: 2026-04-26

Author: ATCP

...
...

A malicious actor distributed a Trojans disguised as the SteamCleaner utility by modifying the original code, packaging it in a signed InnoSetup installer, and hosting it on multiple GitHub repositories and redirection pages commonly used for cracks/keygens. The installer executes added malicious code that runs an encrypted PowerShell payload to install Node.js and two Node.js backdoor scripts which persist via scheduled tasks and communicate with multiple C2 domains to accept and execute arbitrary commands; the report includes anti-sandbox checks, obfuscation details, sample MD5 hashes, URLs, and FQDNs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.