“Can you test my game?” Fake itch.io pages spread hidden malware to gamers
ID: 1bb0df68-0750-5c05-ba76-8e5e03b6e6c5
STIX ID: report--1bb0df68-0750-5c05-ba76-8e5e03b6e6c5
Feed Name: Malwarebytes Blog
Malwarebytes describes a malicious campaign that impersonates indie game download pages (often spread via Discord DMs from compromised accounts) to distribute a stealthy loader named 'Setup Game.exe'. The loader spawns an encoded PowerShell stager that executes scripts in memory, hides its console, attempts to relaunch with elevated privileges, compiles helper binaries, unpacks a Node.js runtime and native modules into user cache, forces browser closures, and performs checks to avoid sandbox detection before retrieving follow-on payloads; the report provides IOCs (several blogspot domains), detection cues, and remediation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
