logo

Legion Stealer targeting PUBG players

ID: bc6c9e49-9715-5f17-88f8-70bed7bf1b3a

STIX ID: report--bc6c9e49-9715-5f17-88f8-70bed7bf1b3a

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2023-07-29

Date Updated: 2026-07-17

...
...

CRIL identified a malicious GitHub repository disguised as a PUBG bypass that distributes a renamed .Scr executable masquerading as a .sln file; execution drops and launches a .NET-based Legion Stealer which disables Defender, performs anti-analysis checks, harvests browser credentials, cookies, crypto wallets, game session files, and system information, then compresses and exfiltrates stolen data via Discord webhooks. The report includes static indicators (file hashes), a mapped set of MITRE ATT&CK techniques, a detailed description of the infection chain and capabilities, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.