Fake Game Apps Deliver Multi-Stage Infostealers, Steal Crypto and Passwords
Key Takeaways Cybercriminals are distributing multi-stage infostealers disguised as game downloads, mods, and cracks for Windows systems. The attack chain leverages the RenPy game engine and...
Key Takeaways
- Cybercriminals are distributing multi-stage infostealers disguised as game downloads, mods, and cracks for Windows systems.
- The attack chain leverages the RenPy game engine and legitimate Windows utilities like MSBuild to evade detection.
- The primary payload, Amatera Stealer, exfiltrates sensitive data including passwords, cryptocurrency wallet information, browser data, and local files.
- Attackers are employing sophisticated techniques like EtherHiding, which stores command-and-control server addresses on the Ethereum blockchain, to complicate takedowns.
- Users should only download software from official sources and organizations should implement strict software policies and monitor for anomalous activity.
Hackers Deploy Multi-Stage Infostealers via Fake Game Downloads
A sophisticated new campaign is leveraging fraudulent game downloads to infect Windows computers with a multi-stage information stealer. Threat actors are masquerading malicious archives as popular games, modifications, and software cracks, capitalizing on the demand for free or hard-to-find digital content.
Table Of Content
Upon execution, these seemingly innocuous downloaded archives initiate a stealthy infection process. While a user might observe a legitimate-looking loading or installation screen, a complex sequence of hidden programs is secretly deploying Amatera Stealer. This potent malware is engineered to pilfer a wide array of sensitive data, including passwords, browser information, cryptocurrency wallet details, messaging app data, and local files, as detailed in a recent analysis by researchers.
The RenPy Loader Attack Chain
The infection begins when a user executes a file named “Setup.exe” from a downloaded archive. This file initiates RenPy Loader, a sophisticated multi-stage framework that weaponizes the legitimate RenPy open-source game development engine. By embedding malicious Python code within a seemingly benign gaming package, the attackers cleverly disguise their true intent.
The initial stage of RenPy Loader performs anti-analysis checks to detect virtual environments. It then decrypts a hidden ZIP archive and extracts its contents into a temporary directory. To further aid its stealth, it removes the “Mark of the Web” protection from the extracted files, a security feature that flags files downloaded from the internet. Subsequently, it uses the legitimate Windows utility forfiles.exe to launch a batch file, effectively turning a routine installer into the gateway for a more extensive malicious operation.
This batch file then invokes MSBuild, another legitimate Windows build component, to load a compromised .NET library named Nancy. This modified library is responsible for decrypting further data, manipulating network settings, executing anti-forensics measures, and launching yet another hidden component. This technique of abusing trusted Windows utilities like MSBuild to mask malicious activity is a common evasive maneuver, as Malwarebytes said in a report.
The subsequent downloader, GollopDevest.dll, employs an advanced technique known as EtherHiding. This method retrieves its command-and-control (C2) server address from data embedded within the Ethereum blockchain, rather than storing it directly within the malware. This innovative approach significantly complicates detection and takedown efforts, a tactic previously observed in similar blockchain-based malware campaigns. Finally, GollopDevest.dll downloads and decrypts the ultimate payload: Amatera Stealer.
Credentials and Wallets at Risk
Amatera Stealer is designed to harvest information that can be quickly monetized or used for further illicit access. This includes browser passwords, cookies, and session data, which can grant attackers unauthorized entry into email, social media, financial services, and even corporate systems without requiring direct credential input. Furthermore, the theft of cryptocurrency wallets, browser extensions, messaging app data, and local files can lead to immediate and irreversible financial losses for individuals and pose significant risks to organizations.
It is important to note that the final payload delivered by RenPy Loader is not static. Researchers have previously documented the loader distributing other prominent malware families, such as HijackLoader and Lumma Stealer. This adaptability indicates that the operators can readily switch payloads to align with their specific campaign objectives. Users who have been tracking earlier Amatera Stealer activity or <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/32f4ada3-2d2d-4611-b9ae-d5f0638db429/Hackers-Turn-Fake-Games-Into-Multi-Stage-Infostealers-That-Steal-Passwords-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYEXG3EIVHM&Signature=6AE%2BvMkmf86ubXa2CCkDR%2FqrhYQ%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEPr%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCICHOthB7NGgxKUDtFMCUnbP9BSsejuc8jye%2BlJ6q
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.