Posts

Showing posts from July, 2024

Analysing How Malware Is Hidden In Cheating Software

Image
This is first blogpost of my amateur research of free cheating programs available on code sharing platforms. We can often find repositories which contain just an ad to the developer's websites where wannabe cheaters must pay before downloading anything. I check the repos where there the authors release small chunks of code as a method to deceive players who will actually become targets of Trojans. I find free cheating software as a great source of malware samples, because one can be sure that cheaters will do anything to have any advantage over other players, including disabling antiviruses and other system protections. This way the malicious file won't be detected nor removed from the filesystem, moreover, it will be almost instantly opened. Contents: Sample 1. AsyncRAT Repository Dropper Malware Sample 2. Dropper in SCR file Repository Dropper Malware Sample 3. Lumma Stealer Repository Malware Sample 4. RedLine Stealer Repository Dropper Malware Summary Sample 1. AsyncRAT Rep...