logo

Hackers phish finance orgs using trojanized Minesweeper clone

ID: eaeb1362-36ed-56c0-a99f-e9fe94ed600b

STIX ID: report--eaeb1362-36ed-56c0-a99f-e9fe94ed600b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-05-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CERT‑UA and CSIRT‑NBU report a phishing campaign attributed to actor UAC‑0188 that hides malicious Python code inside a legitimate Minesweeper clone; the embedded base64 payload decodes to an MSI installer for SuperOps RMM, enabling remote access. At least five potential breaches of financial and insurance organizations in Europe and the US were identified, and the agencies published IOCs and guidance to treat SuperOps artifacts or network calls as indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.