Starfield themed malware blasts off
ID: 6ee1a582-6080-589b-8966-553bf4c1da37
STIX ID: report--6ee1a582-6080-589b-8966-553bf4c1da37
Feed Name: DoublePulsar
A security researcher found trojanized Starfield game installers uploaded to VirusTotal that are remote access trojans masquerading as the game; the sample (hash ea6af173a3577fa192821f746d701365b759689eb3562ad546230f6da99a18ae) contacts three C2 domains (blank-cbxur.in, blank-jvqsr.in, blank-o7mwe.in), disables Microsoft Defender protections, performs hardware reconnaissance, and attempts to steal Discord tokens. The report warns users against pirated downloads and notes low antivirus detection for at least one sample.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
