News·4 min read

11 Malicious NuGet Packages Pose as Game Cheats to Deploy Windows Surveillance Malware

Socket’s Threat Research Team has uncovered 11 malicious NuGet packages masquerading as game cheats, bots, and “panels” that deliver a Windows surveillance-capable payload named pepesoft.exe. The pack

CS
CyberShield Team
2026-07-15
Share:
11 Malicious NuGet Packages Pose as Game Cheats to Deploy Windows Surveillance Malware

Socket’s Threat Research Team has uncovered 11 malicious NuGet packages masquerading as game cheats, bots, and “panels” that deliver a Windows surveillance-capable payload named pepesoft.exe. The packages were uploaded as .NET command-line tools, also known as DotnetTool packages. They target players of games including Albion Online, GTA5RP, GrandRP, Majestic RP, Lineage 2, Throne and Liberty, […] The post 11 Malicious NuGet Packages Pose as Game Cheats to Deploy Windows Surveillance Malware appeared first on Cyber Security News.

Socket’s Threat Research Team has uncovered 11 malicious NuGet packages masquerading as game cheats, bots, and “panels” that deliver a Windows surveillance-capable payload named pepesoft.exe. The packages were uploaded as .NET command-line tools, also known as DotnetTool packages. They target players of games including Albion Online, GTA5RP, GrandRP, Majestic RP, Lineage 2, Throne and Liberty, Russian Fishing 4, and others. Researchers reported the packages to NuGet and requested their removal, along with suspension of the publisher account. The campaign uses two stages. First, a malicious .NET downloader, installed via NuGet, retrieves and launches the second-stage executable. The payload then collects host information, communicates with operator-controlled cloud services, enforces hardware-based licensing, and, in some versions, enables Telegram-controlled screenshot collection. NuGet Packages Deploy Spyware All 11 packages contain a downloader assembly stored under tools/net8.0/any/. When launched, it displays Russian-language messages resembling a normal updater, such as “Launching, please wait” and “Downloading assets.” The packages use a shared Windows mutex, Global{5BD61028-3D9C-4B4E-AD45-CA4F1B35D0F4}, to prevent multiple instances from running. They also bundle MonoTorrent and Mono. Nat libraries, although the BitTorrent delivery mechanism is dormant in the analyzed samples. Attack chain flow: NuGet DotnetTool downloader stages and launches pepesoft.exe, which reports to Google Sheets, honors a remote HWID ban-list, and (in the direct-bytecode builds) exposes Telegram screenshot control (Source: socket) The downloader attempts to fetch pepesoft.exe from Hugging Face and GitHub Releases infrastructure associated with the username pepegit666. Each malicious package points to a game-specific release tag, such as albion.onlinepanel, gta5rp.com, throne, and trigpanel. The second stage is a PyInstaller-packed Python application. Socket-recovered payloads linked to all package variants and found shared code for cloud configuration retrieval, Google Sheets integration, licensing checks, device fingerprinting, and remote ban-list enforcement. The malware retrieves a service.json configuration file through a Cloudflare Worker, with a fallback to an S3-compatible Selectel storage bucket. It then authenticates with Google Sheets using embedded service account information. Socket’s AI Scanner flagging amazing-x-x@7.7.8 as known malware. The flagged module is the bundled first-stage downloader tools/net8.0/any/amazingrp.dll.(Source: socket) Across the recovered payload set, the malware records licensing and system status in operator-controlled Google spreadsheets. It can bind an activation key to a device using identifiers such as the hardware UUID, disk serial number, MAC address, CPU, motherboard, and GPU. It also checks a remote “banned” worksheet and terminates if the device fingerprint appears on the list. Three direct-bytecode builds targeting Albion, Calculator, and Throne contain more extensive monitoring capabilities. These variants collect the username, hostname, Windows version, screen resolution, processor details, GPU data, active-window metadata, internet status, IP-based location information, and network connection counts, Socket said. They also include Telegram bot handlers that can capture and transmit screenshots. Commands such as /screen and /pscreen can capture a game window or the Pepesoft application window. In contrast, some Throne-related functions can capture the full screen. Any sensitive material visible in the captured area including browser sessions, cryptocurrency wallets, passwords, private messages, or recovery phrases could be exposed. Indicators of Compromise IOC typeIndicatorContextMalicious NuGet packagealbion-x-xMasquerades as an Albion Online utilityMalicious NuGet packageamazing-x-xMasquerades as an Amazing RP utility Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google. The post 11 Malicious NuGet Packages Pose as Game Cheats to Deploy Windows Surveillance Malware appeared first on Cyber Security News.

Share:

Join the Discussion

Comments coming soon. Follow us on social media for real-time discussions.