HackMyIP
← Back to News
2026-07-16 The Hacker News

Game Cheat NuGet Packages and Fake Installers Deploy RATs and Spyware

MalwareSupply ChainThreat Intel

Cybersecurity researchers have uncovered 11 malicious NuGet packages posing as .NET command-line tools marketed as game cheats, bots, and automation panels. According to Socket, these packages function as first-stage downloaders that fetch a Python-based surveillance payload called "pepesoft.exe" from GitHub Releases and Hugging Face under the username "pepegit666," with a dormant BitTorrent fallback built in for redundancy. The recovered payloads use AWS-style key material to retrieve remote configurations, authenticate to Google Sheets, bind activations to hardware identifiers, and honor a remote HWID/UUID ban-list—giving operators persistent control over infected hosts. The larger game-automation payloads also expose Telegram bot commands capable of exfiltrating screenshots to attacker-controlled chats, a stark reminder that software supply chain attacks often masquerade as convenience tools.

In a parallel campaign tracked since at least June 2025, Cisco Talos is reporting activity from UAT-11795, a sophisticated Russian-speaking, financially motivated adversary targeting users across the U.S. and Europe. The group delivers a Python-based remote access tool dubbed Starland RAT alongside a PowerShell-based C2 memory implant called WLDR, packaged inside trojanized installers for legitimate software including MobaXterm, WebEx, Zoom, DBeaver, and FaceIT. The attack chain abuses ClickFix lures to distribute HTA scripts, which run trojanized installers that ultimately stage WLDR through an encrypted beaconing and Runspace execution engine. UAT-11795 has additionally been linked to CastleStealer and Remcos RAT deployments, with the malware designed to harvest credentials, cryptocurrency wallet assets, and Active Directory information.

Defenders should treat any unsolicited installer—particularly those promising game enhancements or pirated software—as a high-risk artifact. Given the credential theft focus across both campaigns, users can run their credentials through a breach checker to determine whether harvested logins may already be circulating in dark web repositories. Operators investigating suspected infections can scan exposed endpoints with a port scanner to identify unauthorized listeners, while security teams mapping the Starland RAT and WLDR C2 infrastructure can pivot on associated domains via WHOIS lookups to attribute overlapping infrastructure and accelerate containment.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Browser Fingerprint →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a VPN? →How websites track you →Browser fingerprinting explained →