Legion Stealer targeting PUBG players
ID: bc6c9e49-9715-5f17-88f8-70bed7bf1b3a
STIX ID: report--bc6c9e49-9715-5f17-88f8-70bed7bf1b3a
Feed Name: Cyble Blog
CRIL identified a malicious GitHub repository disguised as a PUBG bypass that distributes a renamed .Scr executable masquerading as a .sln file; execution drops and launches a .NET-based Legion Stealer which disables Defender, performs anti-analysis checks, harvests browser credentials, cookies, crypto wallets, game session files, and system information, then compresses and exfiltrates stolen data via Discord webhooks. The report includes static indicators (file hashes), a mapped set of MITRE ATT&CK techniques, a detailed description of the infection chain and capabilities, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
