Gamers, get ready: scammers disguise cryptocurrency and password-stealing Scavenger trojans as cheats and mods
ID: ebae3956-278d-5714-b0e2-f82d9516aede
STIX ID: report--ebae3956-278d-5714-b0e2-f82d9516aede
Feed Name: Dr.Web News
Doctor Web researchers describe Trojan.Scavenger, a multi-stage Windows malware family distributed via fake game patches and plugins that exploits DLL Search Order Hijacking to load malicious DLLs into Chromium-based browsers and crypto wallet applications; the malware disables sandboxing and extension verification, modifies/serves tampered extensions from ServiceWorkerCache, hooks V8 and file APIs to harvest mnemonic phrases, private keys, cookies and passwords, and exfiltrates these to C2 servers—Doctor Web added protections and published IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
