Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding
ID: 45300862-3215-5d9f-8144-82c1a3e64b2d
STIX ID: report--45300862-3215-5d9f-8144-82c1a3e64b2d
Feed Name: Malwarebytes Blog
This report analyzes active campaigns distributing a RenPy Loader that masquerades as games/mods/cracks to perform a multi-stage infection: a Ren’Py-based loader unpacks a ZIP, uses a BAT to invoke MSBuild with malicious project files to load a trojanized .NET DLL, and then employs an EtherHiding technique (reading a blockchain value via eth_call) to resolve C2 and download additional stages that ultimately deploy Amatera Stealer (an information-stealer targeting browsers, crypto wallets, and credentials). The write-up includes technical details of the loader, MSBuild abuse, DLL obfuscation, distribution channels, and a set of IOCs (domains, IPs, MD5 hashes) and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
