Site navigation

Trojanized Mario Forever Exploits Gamers in Malware Campaign

Michael Edgar

,

Trojanized Mario Forever
Threat actors are targeting gamers in malware exploits, the latest case uncovered in a malicious version of Super Mario 3: Mario Forever.

The malware campaign was uncovered by researchers from Cyble, a cyber research and intelligence lab. What they found was a trojanized Super Mario Bros game installer that contains three executables: the legitimate game, and two malicious files, “atom.exe” and “java.exe.”

Both malicious files were hidden within the %appdata% directory, helping them avoid detection. The malicious files worked together, with the java.exe file mining cryptocurrency, capitalising on the powerful hardware often associated with gaming.

The atom.exe file served as a botnet mining client, which managed the mining process and received tasks from the network. 

Alongside the crypto mining, the atom.exe file also retrieved information stealing executables from a command and control server called “wime.exe.” This file is an Umbra Stealer, an information stealer written in C#. 

The Umbra stealer collected sensitive data from the victim system such as screenshots, webcam images, passwords, and crypto wallet information. The stolen data is stored locally before being exfiltrated to the command and control server. 

The Umbral stealer evades detection by disabling Windows Defender or adding its process to the Defender’s execution list. It also disrupts communication between antivirus products and company sites, rendering them less effective. 

Cyble points out that the gaming community is a ripe target for threat actors since games can often be complex in nature, with large file sizes to conceal malware in. Popular franchises, such as Super Mario Bros, also attract a large number of players which threat actors can capitalise on. 


Recommended


Researchers were unable to identify the channels that the games are being distributed through, however they predict the games are being promoted through “malvertising campaigns” on gaming forums and social media. 

Cybil recommends users check system performance and CPU usage for any anomalies. The researchers also advise users to avoid downloading pirated software from untrustworthy sources, which often contain hidden malware. They also advise that users enable automatic software updates, employ antivirus software, and continue to exercise caution when opening untrusted links. 

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data