Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload

https://s3.ru-3.storage.selcloud.ru

TLP:CLEAR
Active

URL

Description

Eleven malicious NuGet packages distributed as .NET command-line tools masquerade as game utilities and cheats for popular games including Albion Online, GTA5RP, GrandRP, and Throne and Liberty. Each package functions as a first-stage downloader that uses DNS-over-HTTPS to bypass local controls, requests UAC elevation to resync system time, and fetches a second-stage PyInstaller payload named pepesoft.exe from GitHub and Hugging Face under username pepegit666. The payload binds to hardware fingerprints, enforces licensing through Google Sheets telemetry, honors remote ban-lists, and in three variants exposes Telegram bot commands enabling screenshot capture and remote control. All packages share identical AWS credentials and mutex identifiers, linking them to a single Russian-speaking operator running a commercial game-automation service marketed through pepesoft.ru and Telegram channel pepesoft777.

Sightings (0)

No sightings recorded yet

Details

Name / Label
11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload
Pattern Type
STIX
Confidence
75%
Valid From
Jul 15, 2026 22:00
Total Sightings
0
Added
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of https://s3.ru-3.storage.selcloud.ru

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.