The High Cost of ‘Free’: How PiviGames Became a Lovecraftian Malware Hub for HijackLoader and ACRStealer
ID: ccebe526-bf56-5614-aa19-ca2398ccc141
STIX ID: report--ccebe526-bf56-5614-aa19-ca2398ccc141
Feed Name: securityonline.info
G DATA analysis finds that the Spanish pirated-games site PiviGames has become an active malware distribution hub: hidden JavaScript and malvertising redirect victims to a MediaFire-hosted ZIP containing a malicious Setup.exe that sideloads Conduit.Broker.dll via HijackLoader to deliver ACRStealer. The multi-stage infection includes sophisticated obfuscation, AV and UAC bypass techniques, and has resulted in real account takeovers; recommended mitigations include avoiding pirated software, enabling MFA, and trusting endpoint protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
