11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload
Eleven malicious NuGet DotnetTool packages masquerading as game cheats deliver a two-stage Windows payload. The first-stage .NET downloader resolves GitHub hosts via DNS-over-HTTPS to bypass local DNS controls, requests UAC elevation to resync the system clock, and fetches pepesoft.exe from GitHub Releases and Hugging Face. The second-stage PyInstaller-packed Python payload exfiltrates hardware fingerprints, system information, IP geolocation, and screenshots to Google Sheets and Telegram, with a server-side ban-list and hardware binding for licensing enforcement across all recovered builds.
- domainbots[.]pepesoft[.]ruOperator storefront marketing paid game-automation panels with Telegram control; linked from payload Flet UI
- domaincalm-voice-9797[.]888c888x888[.]workers[.]devCloudflare Worker endpoint passed to payload as AWS_CONFIG_KEY environment variable; used to fetch service.json remote configuration
- domains3[.]ru-3[.]storage[.]selcloud[.]ruSelectel S3-compatible storage endpoint used as fallback for retrieving service.json when Cloudflare Worker fetch fails; bucket name 'zfile'
- ip196[.]16[.]3[.]71Hardcoded authenticated HTTP proxy (port 9528) used by 8 PyArmor-protected payloads to reroute Google Sheets traffic when direct Google access is blocked
- mutexGlobal\{5BD61028-3D9C-4B4E-AD45-CA4F1B35D0F4}Shared process mutex created by all 11 downloader packages to enforce single-instance execution; GUID is derived from the hardcoded AWS-style access key value
- sha256011926de3d0cc2b970627b9bf0de003e731f8576602dff756d2ab54a9de61972rmrp.dll downloader assembly (rmrp-x-x package)
- sha25601d2afea0f2201a3b59765a1a60ba324ff4b8fdd25f23a0e05824b97f195b27cPyArmor-protected gtaobus.pyc entrypoint (Trigger)
- sha25617b1d836c2f15a97be0350879943b04e14bc076cf09e31df0d73258ee10f7e7cPyArmor-protected gtaobus.pyc entrypoint (Russian Fishing 4)
- sha25623808e7638f7a00b1ef9b9f4ca524f8a46cf63be6f6b79fec8e4a3fd1cc82a1etrigger.dll downloader assembly (trigger-x-x package)
- sha25623e4d8af5425dae022793450190c8d30809b2986dd879eb4bff557cdacf49c86PyArmor-protected gtaobus.pyc entrypoint (GrandRP)
- sha2562a4fed04d792b9c2fdf9c1456a08ca23eda5fef50c0b409ab294ad489e12d801PyArmor-protected gtaobus.pyc entrypoint (Lineage 2)
- sha256476c6f36a22156e53548a87291989a21d6c905dcbd9e1bf68ff5bc12e5c8bb07gtaobus.pyc entry module (Throne direct-bytecode payload)
- sha2564d13f1136b13c871c65141b77ec7208488334ac4be511800196adcd328666305majestic.dll downloader assembly (majestic-x-x package)
- sha256567952daf0ab7b36b017aac9963791188dea0fbf2e99c7cc6f6652ee540f4840gtaobus.pyc entry module (Albion direct-bytecode payload)
- sha2565d9843126db4223dc2a8a9cd4a627286fe1a6345e33b28e9c98b5fe56fe89da6pepesoft.exe second-stage payload (RMRP)
- sha2565f3a9ebf7039097b3cdbca8609b5b68af07eeb1dbf716ba2817a97fc7c543854setup.dll downloader assembly (throne-x-x package)
- sha2566c1f828e4d8395dde8293868c65ba8d86b3b9672ebbbb16e932624706d37d832pepesoft.exe second-stage payload (Lineage 2)
- sha2566cbd4bc491deb11040e2b2f91b0b4e129af551a802fc78cb42e0e985297ef44cpepesoft.exe second-stage payload (Majestic)
- sha2566eefe9d5f030d403c72bd4e4caf5bbb9dbc2bd5e15ebb07de153494f458e5eb9pepesoft.exe second-stage payload (GrandRP)
- sha256774e40046f353e3f916f39e3d13d6499da35705a479cfb89288c21017aaf5461PyArmor-protected gtaobus.pyc entrypoint (Amazing RP)
- sha25679c09e1ffb4804c14ff27d41ec08d4390455c92d65717be0aeeec2697297d76arusfish4.dll downloader assembly (rusfish4-x-x package)
- sha2567e42d25e707d29d5d185a4c5dc71019f744e88a30b66bbf06949194ff32dbc48PyArmor-protected gtaobus.pyc entrypoint (Majestic)
- sha2568ab256dd839aec6638cd46374f4a6664e534b9341bbcdfd9b763e5a27c51ddb7pepesoft.exe second-stage payload (GTA5RP)
- sha256900ddb81d27e03967209fee4d17d13deb68eef0e1f10936eb520ca10575cb49ecalculator.dll downloader assembly (calc-x-x package)
- sha25695577498d23fe750221a5badfc25b5e9f020dcf4d80c79a019b090e3c3b0a32aPyArmor-protected gtaobus.pyc entrypoint (GTA5RP)
- sha2569a2091e6625fc11cfd8f39c17aa271604e66322ee045028946274b988103e35bamazingrp.dll downloader assembly (amazing-x-x package)
- sha256a2a5e473dba85959b21b7e8a184bc255d5f2dacdf7411b91d212fb1217d2518bpepesoft.exe second-stage payload (Trigger)
- sha256ab58a90eb3682c6dc3389cd700a64f68a19c0dac3d0fa8e3df97ae041f96d4e1grandrp.dll downloader assembly (grandrp-x-x package)
- sha256ba7fc544994f126cb7485ce52d265d2f32e93c4f1ea1fcd6fcdee3918f27197981d243bd2c585b0f4821__mypyc.cp313-win_amd64.pyd, identical compiled charset_normalizer dependency across three unpacked payloads
- sha256c9f3e7766dbe728d84a1243447faa5f5eba0645bf13089074d128ea7663e7f5bpepesoft.exe second-stage payload (Russian Fishing 4)
- sha256cc853b3e4504c890d275ac2327f18acd7e4c5b99ca056181f3f5694781f2cf45gtaobus.pyc entry module (Calculator direct-bytecode payload)
- sha256d5385526f2f3e52c7d96087611c6cd4e479bf61828400efdb3ca09406d981609SHA-256 hash of albion.dll, the first-stage .NET downloader assembly bundled in the albion-x-x NuGet package
- sha256d59e1914d76499fa51bf861f418c84bda0b48913dc39bd2e73756e326e4ccbb0PyArmor-protected gtaobus.pyc entrypoint (RMRP)
- sha256d9f7ca9f93a7d188d51db308877b15d0beae932ca0bf4705384fbedf54b454c1lineage2.dll downloader assembly (l2-x-x package)
- sha256e6e1049158ceb1971c61388349c81fa6047a7aecb4ff2089ef54a50dcc35dbc0gta5rp.dll downloader assembly (gta5rp-x-x package)
- sha256e8c2618565aa31d7ffe909ebc99040bafcc0ea8df7f5d92fa673bb7ffacb14c9SHA-256 hash of pepesoft.exe second-stage payload for Amazing RP, a PyInstaller-packed Python 3.13 binary
- urlhxxps://discord[.]com/api/webhooks/1156474517871403078/zuHl6xQzdMcFjNrmm9jTiHvCzNbCiQhkYAIGWNUfj7X4KUIpEATekKlSNna6OvyCKaRwDiscord webhook URL hardcoded in direct-bytecode payloads for data exfiltration or telemetry
- urlhxxps://discord[.]com/api/webhooks/1156474527874818088/qS5cJuxEbyIA1s3tZX_A2u6YsKtLUARVPvN77_6fK5QHGdGFHb3JSuCUSDhtouEsyJgkSecond Discord webhook URL hardcoded in direct-bytecode payloads for data exfiltration or telemetry
- urlhxxps://github[.]com/pepegit666/123f53y45ysdf34GitHub repository used for payload staging; contains one release tag per game target, each serving pepesoft.exe as a release asset
- urlhxxps://github[.]com/pepegit666/123f53y45ysdf34/releases/download/albion[.]onlinepanel/pepesoft[.]exeSpecific GitHub Releases download URL for the Albion Online payload; each game has its own release tag (amazing.rp, calculator, grandrp.su, gta5rp.com, lineage2panel, majesticpanel, rmrp, russianfish4, throne, trigpanel)
- urlhxxps://huggingface[.]co/buckets/pepegit666Hugging Face account path used as primary payload download source before GitHub fallback; hosts pepesoft.exe under per-game tag paths
- urlhxxps://huggingface[.]co/buckets/pepegit666/albion[.]onlinepanel/resolve/pepesoft[.]exe?download=trueSpecific Hugging Face download URL for the Albion Online payload; primary download source tried before GitHub fallback
- urlhxxps://t[.]me/pepesoft777Telegram channel linked from the Pepesoft storefront and payload UI; operator uses Telegram for bot control and screenshot delivery
Detection / Hunteropenrouter
What Happened
Security researchers found 11 malicious software packages disguised as game cheating tools on the NuGet platform, which is commonly used by software developers. When someone installs and runs one of these packages, it secretly downloads a program called pepesoft.exe that collects detailed information about the victim's computer — including hardware details, approximate location, and screenshots of what is on their screen — and sends this data to the attacker through Google Sheets and Telegram. The attacker can also remotely control the victim's computer by sending commands through Telegram, including capturing screenshots that may expose passwords or other sensitive information visible on screen. Anyone who installed these packages should uninstall them, delete associated files, and change any passwords that may have been visible while the tool was running. Developers should be cautious about installing unvetted tools from package registries, even from well-known platforms like NuGet.
Key Takeaways
- 11 malicious NuGet DotnetTool packages masquerade as game cheats/bots for Albion Online, GTA5RP, GrandRP, Majestic RP, RMRP, Amazing RP, Lineage 2, Throne and Liberty, and Russian Fishing 4
- First-stage .NET downloader uses DNS-over-HTTPS (dns.google/resolve) to bypass hosts-file and local DNS sinkhole controls, then fetches pepesoft.exe from GitHub Releases and Hugging Face under username pepegit666
- Second-stage PyInstaller-packed Python payload exfiltrates hardware fingerprints, system info, IP geolocation, and screenshots to Google Sheets and Telegram; direct-bytecode builds expose 36 Telegram bot command handlers for remote control
- All 11 packages share the same AWS-style key material and process mutex (Global{5BD61028-3D9C-4B4E-AD45-CA4F1B35D0F4}), linking them to a single toolchain and operator (Pepesoft storefront at bots.pepesoft.ru)
- Eight PyArmor-protected payloads include a hardcoded authenticated HTTP proxy (196.16.3.71:9528) as a fallback for Google Sheets traffic, which can bypass egress filtering of Google services
Affected Systems
- Windows systems (payload is Windows-specific, uses PyInstaller and .NET 8.0)
- NuGet package manager / .NET CLI (dotnet tool install)
- Python 3.13 runtime (PyInstaller bundle target)
- Users of: Albion Online, GTA5RP, GrandRP, Majestic RP, RMRP, Amazing RP, Lineage 2, Throne and Liberty, Russian Fishing 4
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Malicious NuGet DotnetTool packages installed via 'dotnet tool install', masquerading as game cheats and utilities for Russian-community RP servers
- Execution: Downloader DLL resolves GitHub hosts via DNS-over-HTTPS (dns.google/resolve), requests UAC elevation to resync system clock, then fetches pepesoft.exe from Hugging Face or GitHub Releases
- Configuration: pepesoft.exe retrieves service.json from Cloudflare Worker or Selectel S3 fallback using inherited AWS-style credentials, then authenticates to Google Sheets for licensing and telemetry
- Discovery: Payload collects hardware fingerprints (CPU, motherboard, GPU, disk serial, MAC), network connections, keyboard/mouse inventory, admin status, IP geolocation, and active window metadata
- Collection/Exfiltration: Direct-bytecode payloads capture screenshots via Telegram bot commands (/screen, /pscreen, /disconnect) and write detailed telemetry to Google Sheets; PyArmor-protected payloads reroute Sheets traffic through hardcoded proxy if direct access fails
- Impact: Exit handler modifies Windows Installer registry policies and conditionally deletes all non-EXE files and subdirectories from the application's current directory
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
The article provides detailed detection recommendations (alert on dotnet tool install of unknown packages, child powershell.exe with w32tm /resync, dns.google/resolve queries from .NET processes, AWS_CONFIG_KEY environment variable reads) but does not include any specific YARA, Sigma, Snort, Suricata, KQL, SPL, or EQL rule content. Socket's AI scanner is mentioned as detecting the packages but no rule bodies are provided.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | The downloader uses standard Windows processes (powershell.exe, cmd.exe) with suspicious but not unusual arguments. Mutex creation, environment variable injection, and file writes are visible to EDR. However, the PyInstaller-packed Python payload with PyArmor wrapping may limit deep inspection of second-stage behavior. The DNS-over-HTTPS queries to dns.google may appear as legitimate HTTPS traffic. |
| Network Visibility | Medium | The payload abuses legitimate services (GitHub, Hugging Face, Google Sheets, Cloudflare Workers) which may blend with normal developer traffic. DNS-over-HTTPS bypasses system DNS resolution. The hardcoded proxy IP (196.16.3.71:9528) and Selectel S3 endpoint are distinctive network indicators. Discord webhook and Telegram traffic may be visible but could be mistaken for legitimate application usage. |
| Detection Difficulty | Moderate | The TTPs are individually detectable through behavioral analytics, but the abuse of legitimate services (GitHub, Google Sheets, Cloudflare, Hugging Face) for staging and exfiltration requires correlation rather than simple blocklisting. The DNS-over-HTTPS bypass and proxy fallback for Google Sheets traffic add complexity. The shared mutex and hardcoded key values provide strong pivot points for detection. |
Required Log Sources
- Sysmon Event ID 1 (Process Create) — for dotnet.exe spawning powershell.exe and cmd.exe
- Sysmon Event ID 3 (Network Connect) — for DNS-over-HTTPS and payload download traffic
- Sysmon Event ID 11 (FileCreate) — for pepesoft.exe, version.meta, ./libgg/ artifacts
- Sysmon Event ID 13 (RegistryValueSet) — for Windows Installer policy modifications
- Sysmon Event ID 17/18 (PipeEvent) — for mutex creation
- PowerShell Script Block Logging (Event ID 4104) — for w32tm /resync commands
- Windows Security Event ID 4688 (Process Creation) — as fallback if Sysmon unavailable
- DNS query logs — for DoH bypass detection
- NuGet package installation logs — for supply chain alerting
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for .NET tool installations (dotnet.exe with tool install arguments) followed shortly by child powershell.exe processes with hidden window style and w32tm arguments, which would indicate the clock resync behavior described in T1059.001. | Sysmon Event ID 1 (Process Create) with parent-child process correlation; PowerShell Script Block Logging (Event ID 4104) | Initial Access / Execution | Low — legitimate .NET tools rarely spawn hidden PowerShell to resync system clocks; w32tm /resync from a package installer is highly anomalous. |
| Consider hunting for non-browser processes making HTTPS requests to dns.google/resolve, which would indicate DNS-over-HTTPS usage designed to bypass local DNS controls as described in T1071.001. | Sysmon Event ID 3 (Network Connect) filtered for dns.google destination; DNS proxy logs; TLS SNI logs | Defense Evasion / Command and Control | Medium — some legitimate applications and browsers use DNS-over-HTTPS; focus on dotnet.exe or non-browser processes making these requests. |
| Consider hunting for processes that set AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_CONFIG_KEY environment variables before spawning child executables, which would indicate the credential injection pattern used to configure the payload. | Sysmon Event ID 1 with command-line capture; EDR environment variable monitoring; Windows Event Log for process environment changes | Execution / Configuration | Low-Medium — legitimate AWS SDK usage sets these variables, but setting all three including AWS_CONFIG_KEY pointing to a Cloudflare Worker URL is anomalous. |
| Consider hunting for PyInstaller-packed executables creating files in ./libgg/ directories or writing screenshot PNG files, which would indicate the Telegram screenshot exfiltration behavior described in T1113. | Sysmon Event ID 11 (FileCreate); EDR file write monitoring with path pattern matching | Collection / Exfiltration | Low — the ./libgg/ path and screenshot naming pattern are specific to this payload family. |
| Consider hunting for processes modifying or deleting values under HKLM\Software\Policies\Microsoft\Windows\Installer, particularly DisableLogging and DisableMSI, which would indicate the exit handler behavior described in T1112. | Sysmon Event ID 13 (RegistryValueSet) and Event ID 12 (RegistryValueDelete); Windows Security Event ID 4657 | Impact / Defense Evasion | Low — modifications to Windows Installer policy from a non-installer process are highly anomalous. |
Control Gaps
- DNS sinkholing and hosts-file blocking are bypassed by DNS-over-HTTPS resolution via dns.google/resolve
- Egress filtering of Google services (sheets.googleapis.com, www.googleapis.com) may not stop telemetry exfiltration from PyArmor-protected payloads that reroute through hardcoded HTTP proxy
- Cloudflare Workers traffic may blend with legitimate CDN/serverless traffic and evade domain-based blocking
- GitHub Releases and Hugging Face are legitimate services that may not be blocked in typical egress policies
- Standard AV signatures may not detect PyArmor-protected Python payloads or .NET downloader assemblies without specific hash matching
Key Behavioral Indicators
- Process creating mutex named Global{5BD61028-3D9C-4B4E-AD45-CA4F1B35D0F4}
- dotnet.exe spawning powershell.exe with -WindowStyle Hidden and w32tm /resync arguments
- Non-browser process making HTTPS requests to dns.google/resolve endpoint
- Process setting AWS_CONFIG_KEY environment variable before spawning child executable
- cmd.exe /C executing .tmp files from ./_ directory
- PyInstaller bundle creating files in ./libgg/ directory path
- Process modifying HKLM\Software\Policies\Microsoft\Windows\Installer registry values on exit
- Files named pepesoft.exe, gtaobus.pyc, or version.meta appearing in unexpected locations
- Process making outbound connections to 196.16.3.71 on port 9528 (authenticated HTTP proxy)
- Batch file generation with rmdir /s /q and PowerShell Remove-Item -Recurse patterns for directory cleanup
False Positive Assessment
Low — the shared mutex GUID, hardcoded AWS-style key values, specific file paths (./libgg/, pepesoft.exe, gtaobus.pyc), and operator infrastructure (bots.pepesoft.ru, pepegit666 GitHub/Hugging Face accounts) are highly specific to this campaign. The main false positive risk comes from legitimate use of the abused platforms (GitHub, Hugging Face, Google Sheets, dns.google), but the specific URLs, paths, and behavioral patterns described are distinctive enough to minimize false positives.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the Cloudflare Worker endpoint (calm-voice-9797.888c888x888.workers.dev), Selectel S3 endpoint (s3.ru-3.storage.selcloud.ru), HTTP proxy (196.16.3.71:9528), and operator storefront (bots.pepesoft.ru) at your egress proxy or firewall.
- Consider alerting on 'dotnet tool install' commands for unknown or game-cheat-themed package names in your EDR or SIEM, if your tooling supports process command-line monitoring.
- If applicable, hunt for the shared mutex GUID, pepesoft.exe, gtaobus.pyc, ./libgg/ artifacts, and %LOCALAPPDATA%\Windows Src\key*.txt files across your endpoint fleet.
- Consider blocking the specific GitHub and Hugging Face staging URLs (github.com/pepegit666/123f53y45ysdf34 and huggingface.co/buckets/pepegit666) at your web proxy or next-generation firewall.
Infrastructure Hardening
- Evaluate whether your DNS filtering or proxy can detect and block DNS-over-HTTPS queries to dns.google/resolve from non-browser processes, particularly dotnet.exe.
- Consider implementing package allowlisting or private NuGet feeds for development pipelines to prevent installation of unvetted packages.
- If supported by your tooling, consider blocking the Discord webhook URLs and Telegram channel associated with this campaign at the proxy level.
- Evaluate whether egress filtering of Google Sheets API traffic from non-Google processes would be feasible without impacting legitimate business workflows.
User Protection
- Consider educating developers about the risks of installing unvetted NuGet tools, especially those claiming to be game cheats, bots, or panels.
- If applicable, evaluate whether your EDR can detect and alert on PyInstaller-packed executables creating screenshot files or writing to ./libgg/ directories.
- Consider monitoring for processes that set AWS-style environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_CONFIG_KEY) before spawning child processes.
- If your EDR supports host isolation, consider pre-staging isolation playbooks for endpoints found running pepesoft.exe or any of the 11 malicious package commands.
Security Awareness
- Consider incorporating supply chain attack scenarios into existing security awareness programs, emphasizing that package registries like NuGet can deliver executable malware disguised as developer tools.
- If applicable, remind developers to review the tools/ contents of NuGet packages before installation and to be suspicious of packages that bundle networking stacks like MonoTorrent or that carry no source repository.
- Consider adding guidance to existing developer onboarding about the risk of installing game-cheat or game-utility themed packages on development machines, as these can serve as initial access vectors for broader compromise.
MITRE ATT&CK Mapping
Resource Development
Initial Access
Execution
Stealth
Defense Impairment
Discovery
Collection
Command and Control
Exfiltration
Additional IOCs
- Urls:
hxxps://discord[.]com/api/webhooks/1156474517871403078/zuHl6xQzdMcFjNrmm9jTiHvCzNbCiQhkYAIGWNUfj7X4KUIpEATekKlSNna6OvyCKaRw- Discord webhook URL hardcoded in direct-bytecode payloads for data exfiltration or telemetryhxxps://discord[.]com/api/webhooks/1156474527874818088/qS5cJuxEbyIA1s3tZX_A2u6YsKtLUARVPvN77_6fK5QHGdGFHb3JSuCUSDhtouEsyJgk- Second Discord webhook URL hardcoded in direct-bytecode payloads for data exfiltration or telemetryhxxps://github[.]com/pepegit666/123f53y45ysdf34/releases/download/albion.onlinepanel/pepesoft.exe- Specific GitHub Releases download URL for the Albion Online payload; each game has its own release tag (amazing.rp, calculator, grandrp.su, gta5rp.com, lineage2panel, majesticpanel, rmrp, russianfish4, throne, trigpanel)hxxps://huggingface[.]co/buckets/pepegit666/albion.onlinepanel/resolve/pepesoft.exe?download=true- Specific Hugging Face download URL for the Albion Online payload; primary download source tried before GitHub fallback
- File Hashes:
9a2091e6625fc11cfd8f39c17aa271604e66322ee045028946274b988103e35b(SHA256) - amazingrp.dll downloader assembly (amazing-x-x package)900ddb81d27e03967209fee4d17d13deb68eef0e1f10936eb520ca10575cb49e(SHA256) - calculator.dll downloader assembly (calc-x-x package)ab58a90eb3682c6dc3389cd700a64f68a19c0dac3d0fa8e3df97ae041f96d4e1(SHA256) - grandrp.dll downloader assembly (grandrp-x-x package)e6e1049158ceb1971c61388349c81fa6047a7aecb4ff2089ef54a50dcc35dbc0(SHA256) - gta5rp.dll downloader assembly (gta5rp-x-x package)d9f7ca9f93a7d188d51db308877b15d0beae932ca0bf4705384fbedf54b454c1(SHA256) - lineage2.dll downloader assembly (l2-x-x package)4d13f1136b13c871c65141b77ec7208488334ac4be511800196adcd328666305(SHA256) - majestic.dll downloader assembly (majestic-x-x package)011926de3d0cc2b970627b9bf0de003e731f8576602dff756d2ab54a9de61972(SHA256) - rmrp.dll downloader assembly (rmrp-x-x package)79c09e1ffb4804c14ff27d41ec08d4390455c92d65717be0aeeec2697297d76a(SHA256) - rusfish4.dll downloader assembly (rusfish4-x-x package)5f3a9ebf7039097b3cdbca8609b5b68af07eeb1dbf716ba2817a97fc7c543854(SHA256) - setup.dll downloader assembly (throne-x-x package)23808e7638f7a00b1ef9b9f4ca524f8a46cf63be6f6b79fec8e4a3fd1cc82a1e(SHA256) - trigger.dll downloader assembly (trigger-x-x package)6eefe9d5f030d403c72bd4e4caf5bbb9dbc2bd5e15ebb07de153494f458e5eb9(SHA256) - pepesoft.exe second-stage payload (GrandRP)8ab256dd839aec6638cd46374f4a6664e534b9341bbcdfd9b763e5a27c51ddb7(SHA256) - pepesoft.exe second-stage payload (GTA5RP)6c1f828e4d8395dde8293868c65ba8d86b3b9672ebbbb16e932624706d37d832(SHA256) - pepesoft.exe second-stage payload (Lineage 2)6cbd4bc491deb11040e2b2f91b0b4e129af551a802fc78cb42e0e985297ef44c(SHA256) - pepesoft.exe second-stage payload (Majestic)5d9843126db4223dc2a8a9cd4a627286fe1a6345e33b28e9c98b5fe56fe89da6(SHA256) - pepesoft.exe second-stage payload (RMRP)c9f3e7766dbe728d84a1243447faa5f5eba0645bf13089074d128ea7663e7f5b(SHA256) - pepesoft.exe second-stage payload (Russian Fishing 4)a2a5e473dba85959b21b7e8a184bc255d5f2dacdf7411b91d212fb1217d2518b(SHA256) - pepesoft.exe second-stage payload (Trigger)ba7fc544994f126cb7485ce52d265d2f32e93c4f1ea1fcd6fcdee3918f271979(SHA256) - 81d243bd2c585b0f4821__mypyc.cp313-win_amd64.pyd, identical compiled charset_normalizer dependency across three unpacked payloads567952daf0ab7b36b017aac9963791188dea0fbf2e99c7cc6f6652ee540f4840(SHA256) - gtaobus.pyc entry module (Albion direct-bytecode payload)cc853b3e4504c890d275ac2327f18acd7e4c5b99ca056181f3f5694781f2cf45(SHA256) - gtaobus.pyc entry module (Calculator direct-bytecode payload)476c6f36a22156e53548a87291989a21d6c905dcbd9e1bf68ff5bc12e5c8bb07(SHA256) - gtaobus.pyc entry module (Throne direct-bytecode payload)774e40046f353e3f916f39e3d13d6499da35705a479cfb89288c21017aaf5461(SHA256) - PyArmor-protected gtaobus.pyc entrypoint (Amazing RP)23e4d8af5425dae022793450190c8d30809b2986dd879eb4bff557cdacf49c86(SHA256) - PyArmor-protected gtaobus.pyc entrypoint (GrandRP)95577498d23fe750221a5badfc25b5e9f020dcf4d80c79a019b090e3c3b0a32a(SHA256) - PyArmor-protected gtaobus.pyc entrypoint (GTA5RP)2a4fed04d792b9c2fdf9c1456a08ca23eda5fef50c0b409ab294ad489e12d801(SHA256) - PyArmor-protected gtaobus.pyc entrypoint (Lineage 2)7e42d25e707d29d5d185a4c5dc71019f744e88a30b66bbf06949194ff32dbc48(SHA256) - PyArmor-protected gtaobus.pyc entrypoint (Majestic)d59e1914d76499fa51bf861f418c84bda0b48913dc39bd2e73756e326e4ccbb0(SHA256) - PyArmor-protected gtaobus.pyc entrypoint (RMRP)17b1d836c2f15a97be0350879943b04e14bc076cf09e31df0d73258ee10f7e7c(SHA256) - PyArmor-protected gtaobus.pyc entrypoint (Russian Fishing 4)01d2afea0f2201a3b59765a1a60ba324ff4b8fdd25f23a0e05824b97f195b27c(SHA256) - PyArmor-protected gtaobus.pyc entrypoint (Trigger)
- Registry Keys:
HKLM\Software\Policies\Microsoft\Windows\Installer- Windows Installer policy subkey modified by direct-bytecode payload exit handler; deletes DisableLogging and DisableMSI values if they exist
- File Paths:
tools/net8.0/any/- Directory within NuGet package where downloader DLL assemblies are placed (e.g., albion.dll, amazingrp.dll, setup.dll)pepesoft.exe- Second-stage PyInstaller-packed Python payload downloaded and executed by all 11 packagesgtaobus.pyc- Top-level Python entry module in pepesoft.exe; decrypts and executes embedded application code via Fernet and exec()81d243bd2c585b0f4821__mypyc.cp313-win_amd64.pyd- Compiled charset_normalizer mypyc dependency, byte-for-byte identical across three unpacked direct-bytecode payloads./libgg/chat_ids.txt- File storing Telegram chat IDs after /start command; grants remote-control surface to any chat that completes /start./libgg/screenshot_test.png- Screenshot file created by Telegram /screen command capturing GTA process window./libgg/disconnect_screenshot.png- Full-screen screenshot created by Telegram /disconnect command./libgg/2_screenshot.png- Fixed-region status screenshot created by Throne fishing-monitoring code (series 2 through 5)./token.txt- Token file created by payload for local credential or activation storagecredentials.txt- Credentials file created by payload%LOCALAPPDATA%\Windows Src\key*.txt- Activation key files stored by payload in Windows Src directory%LOCALAPPDATA%\Windows Src- Payload working directory for activation key storage%APPDATA%\pepesoft- Payload configuration directoryversion.meta- Local cache file storing Last-Modified timestamp from payload download HEAD requestshutdown.bat- Generated batch file for exit cleanup; conditionally deletes non-EXE files and subdirectories when exitadaptive is trueDocuments\app_settings.json- Configuration file read by exit handler to check exitadaptive cleanup setting
- Command Lines:
- Purpose: Synchronize Windows system clock before payload download; requests UAC elevation via runas verb (10 of 11 packages) | Tools:
powershell.exe,w32time,w32tm| Stage: Pre-download |powershell.exe -NoProfile -WindowStyle Hidden -Command - Purpose: Execute downloaded pepesoft.exe payload from randomly named .tmp file in ./_ directory | Tools:
cmd.exe| Stage: Execution |cmd.exe /C - Purpose: Install malicious NuGet package as .NET global tool | Tools:
dotnet| Stage: Initial Access |dotnet tool install
- Purpose: Synchronize Windows system clock before payload download; requests UAC elevation via runas verb (10 of 11 packages) | Tools:
- Other:
albion-x-x- Malicious NuGet DotnetTool package targeting Albion Online; contains albion.dll downloaderamazing-x-x- Malicious NuGet DotnetTool package targeting Amazing RP; version 7.7.8 observed; contains amazingrp.dll downloadercalc-x-x- Malicious NuGet DotnetTool package with calculator theme; only package without clock resync or cleanup routines; contains calculator.dllgrandrp-x-x- Malicious NuGet DotnetTool package targeting GrandRP; contains grandrp.dll downloadergta5rp-x-x- Malicious NuGet DotnetTool package targeting GTA5RP; contains gta5rp.dll downloaderl2-x-x- Malicious NuGet DotnetTool package targeting Lineage 2; contains lineage2.dll downloadermajestic-x-x- Malicious NuGet DotnetTool package targeting Majestic RP; contains majestic.dll downloaderrmrp-x-x- Malicious NuGet DotnetTool package targeting RMRP; contains rmrp.dll downloaderrusfish4-x-x- Malicious NuGet DotnetTool package targeting Russian Fishing 4; contains rusfish4.dll downloaderthrone-x-x- Malicious NuGet DotnetTool package targeting Throne and Liberty; contains setup.dll downloadertrigger-x-x- Malicious NuGet DotnetTool package with trigger-bot theme; contains trigger.dll downloader5bd610283d9c4b4ead45ca4f1b35d0f4- Hardcoded AWS-style access key value shared across all 11 packages; set as AWS_ACCESS_KEY_ID environment variable for child payload; derived from mutex GUID with dashes removed21b4be57bd3743738393f44d9464e212- Hardcoded AWS-style secret key value shared across all 11 packages; set as AWS_SECRET_ACCESS_KEY environment variable for child payloadpepegit666- Operator username shared across GitHub, Hugging Face, and NuGet accounts used for payload staging and package publishing