11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload
ID: 17ba946b-73c7-55d2-961a-6e8bdcae7ce7
STIX ID: report--17ba946b-73c7-55d2-961a-6e8bdcae7ce7
Feed Name: Socket Blog
**Executive summary:** Socket’s Threat Research Team analyzed 11 malicious NuGet DotnetTool packages that masquerade as game utilities and download a staged PyInstaller Windows payload (pepesoft.exe) from GitHub/Hugging Face under the operator "pepegit666"; the multi-stage toolset uses DNS-over-HTTPS resolution, elevation for clock resync, embedded AWS-style credentials to retrieve remote configuration, Google Sheets-backed telemetry/licensing (including a remote ban-list and hardware binding), and in some builds Telegram-based screenshot/remote-control features — the report includes behavioral analysis, recovered payloads, IOCs (hashes, URLs, keys, mutex), and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
