logo

Trojanized Mario Installer Spreads SupremeBot Malware

ID: 8d01835f-8b29-5bf1-a292-73b5d1df3cee

STIX ID: report--8d01835f-8b29-5bf1-a292-73b5d1df3cee

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2026-07-07

Date Updated: 2026-07-20

...
...

CRIL identified a trojanized Super Mario Forever NSIS installer (SHA256 e9cc8222...) that drops three executables—one genuine game and two malicious binaries (java.exe XMR miner and atom.exe SupremeBot)—which establish persistence, connect to duckdns C2 endpoints to receive mining configurations, download a Themida-packed wime.exe that loads the open-source Umbral stealer, and exfiltrate stolen credentials and crypto-wallet data via Discord webhooks; IOCs (hashes and URLs), technical behavior, and mitigation guidance are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.