← All stories
● Covered by 1 source · 1 reportHigh impact

Cybersecurity Threats: Spyware from Game Cheats and Fake Installer RATs Target Users

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Malicious NuGet packages act as spyware dropper for 'pepesoft.exe'.
  • Trojanized installers deliver the Starland RAT to users in U.S. and Europe.
  • Cyber attackers are targeting credentials and cryptocurrency information.

Malicious NuGet Packages Installed as Game Utilities

Cybersecurity researchers reported the presence of 11 malicious NuGet packages masked as .NET command-line tools. These packages refer to themselves as game utilities, with their primary function being to download and execute a second-stage Python payload named 'pepesoft.exe'.

The payload employs AWS-style keys to retrieve remote configurations and can communicate with Google Sheets. It is also designed to send screenshots via Telegram bot commands.

Trojanized Software Installers Used by UAT-11795

The financially motivated group UAT-11795 has been running campaigns using trojanized installers for various software, including developer tools and gaming applications. This has been ongoing since at least June 2025, targeting users in the U.S. and Europe. They deploy the Starland RAT and the WLDR command-and-control memory implant.

The WLDR agent showcases advanced capabilities, including encrypted communication and a Runspace execution engine, enabling it to execute further payloads. Victims’ credentials and cryptocurrency wallets are specific targets of the malware.

Impact and Response

The majority of infections are reported in the U.S. with few impacts noted in Germany, indicating a geographic targeting strategy. Organizations may need to enhance security measures against such sophisticated threats. Immediate awareness and responsiveness are essential to mitigate potential damage.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity researchers identified malicious NuGet packages disguised as game utilities that install spyware. Additionally, a financially motivated group is using trojanized software installers to deploy a sophisticated remote access tool aimed at U.S. and European users.