Fake cheat lures gamers into spreading infostealer malware
ID: cdb0e3f8-8323-5ac3-a453-b12ebbab2fb8
STIX ID: report--cdb0e3f8-8323-5ac3-a453-b12ebbab2fb8
Feed Name: Bleeping Computer
A Redline-linked info-stealer is being pushed as a fake game cheat ('Cheat Lab' / 'Cheater Pro') via ZIP installers hosted through Microsoft vcpkg GitHub links. The payload uses uncompiled Lua bytecode compiled at runtime (compiler.exe + lua51.dll + readme.txt) to evade detection, injects into legitimate processes, establishes persistence (scheduled tasks and ProgramData fallback), and communicates with a C2 server to exfiltrate screenshots and system information; the campaign uses a social-engineering lure promising a free licensed copy if victims recruit friends.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
