logo

Starfield themed malware blasts off

ID: 6ee1a582-6080-589b-8966-553bf4c1da37

STIX ID: report--6ee1a582-6080-589b-8966-553bf4c1da37

Feed Name: DoublePulsar

Threat Score
65/100

Date Published: 2023-08-19

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

A security researcher found trojanized Starfield game installers uploaded to VirusTotal that are remote access trojans masquerading as the game; the sample (hash ea6af173a3577fa192821f746d701365b759689eb3562ad546230f6da99a18ae) contacts three C2 domains (blank-cbxur.in, blank-jvqsr.in, blank-o7mwe.in), disables Microsoft Defender protections, performs hardware reconnaissance, and attempts to steal Discord tokens. The report warns users against pirated downloads and notes low antivirus detection for at least one sample.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.