logo

“Can you test my game?” Fake itch.io pages spread hidden malware to gamers

ID: 1bb0df68-0750-5c05-ba76-8e5e03b6e6c5

STIX ID: report--1bb0df68-0750-5c05-ba76-8e5e03b6e6c5

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2025-10-08

Date Updated: 2026-04-28

...
...

Malwarebytes describes a malicious campaign that impersonates indie game download pages (often spread via Discord DMs from compromised accounts) to distribute a stealthy loader named 'Setup Game.exe'. The loader spawns an encoded PowerShell stager that executes scripts in memory, hides its console, attempts to relaunch with elevated privileges, compiles helper binaries, unpacks a Node.js runtime and native modules into user cache, forces browser closures, and performs checks to avoid sandbox detection before retrieving follow-on payloads; the report provides IOCs (several blogspot domains), detection cues, and remediation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.