Trojanized Mario Installer Spreads SupremeBot Malware
ID: 8d01835f-8b29-5bf1-a292-73b5d1df3cee
STIX ID: report--8d01835f-8b29-5bf1-a292-73b5d1df3cee
Feed Name: Cyble Blog
CRIL identified a trojanized Super Mario Forever NSIS installer (SHA256 e9cc8222...) that drops three executables—one genuine game and two malicious binaries (java.exe XMR miner and atom.exe SupremeBot)—which establish persistence, connect to duckdns C2 endpoints to receive mining configurations, download a Themida-packed wime.exe that loads the open-source Umbral stealer, and exfiltrate stolen credentials and crypto-wallet data via Discord webhooks; IOCs (hashes and URLs), technical behavior, and mitigation guidance are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
