Blitz Malware: A Tale of Game Cheats and Code Repositories
ID: 18b09a93-7b1b-5357-9fd1-1d7ef53ef8e3
STIX ID: report--18b09a93-7b1b-5357-9fd1-1d7ef53ef8e3
Feed Name: Palo Alto Networks Unit 42
Unit 42 analyzed "Blitz," a two-stage Windows malware campaign distributed via backdoored game cheats advertised on Telegram; the downloader and bot abuse Hugging Face Spaces (FastAPI) for C2 and payload hosting, implement anti-sandbox checks and process injection, perform keylogging, screenshots, file transfer and DDoS, and deploy an XMRig Monero miner; the report includes technical analysis, persistence and evasion details, 289 observed infections across 26 countries (late April snapshot), extensive IOCs (hashes, mutexes, URLs) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
