Powercat malware campaign: Fake game cheats deliver infostealer targeting Discord, Roblox, and crypto wallets
ID: 26191a24-32ef-5f60-bf94-6ef0c8b41188
STIX ID: report--26191a24-32ef-5f60-bf94-6ef0c8b41188
Feed Name: ThreatLocker Blog
Powercat is a multi-stage malware campaign observed in February 2026 that disguises itself as game cheat utilities to infect gamers. The initial EXE profiles hosts and contacts a command domain, a Java-based second-stage loader (jd-gui.jar) is deployed, and a final infostealer DLL/JAR is installed to steal cryptocurrency wallets, browser cookies (via DPAPI), Discord and gaming accounts, and to perform keylogging, screen and webcam capture; the report includes anti-analysis measures, persistence methods, recommended defensive controls, and multiple SHA256 and domain IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
