The malware campaign was uncovered by researchers from Cyble, a cyber research and intelligence lab. What they found was a trojanized Super Mario Bros game installer that contains three executables: the legitimate game, and two malicious files, “atom.exe” and “java.exe.”
Both malicious files were hidden within the %appdata% directory, helping them avoid detection. The malicious files worked together, with the java.exe file mining cryptocurrency, capitalising on the powerful hardware often associated with gaming.
The atom.exe file served as a botnet mining client, which managed the mining process and received tasks from the network.
Alongside the crypto mining, the atom.exe file also retrieved information stealing executables from a command and control server called “wime.exe.” This file is an Umbra Stealer, an information stealer written in C#.
The Umbra stealer collected sensitive data from the victim system such as screenshots, webcam images, passwords, and crypto wallet information. The stolen data is stored locally before being exfiltrated to the command and control server.
The Umbral stealer evades detection by disabling Windows Defender or adding its process to the Defender’s execution list. It also disrupts communication between antivirus products and company sites, rendering them less effective.
Cyble points out that the gaming community is a ripe target for threat actors since games can often be complex in nature, with large file sizes to conceal malware in. Popular franchises, such as Super Mario Bros, also attract a large number of players which threat actors can capitalise on.
Recommended
- Is “Freedom of Choice” Impacting Tech Subject Uptake at Schools?
- Will AI Change the Workforce Structure? It Already Has
- Report: CX and EX are Key Drivers in Cloud and AI Adoption
Researchers were unable to identify the channels that the games are being distributed through, however they predict the games are being promoted through “malvertising campaigns” on gaming forums and social media.
Cybil recommends users check system performance and CPU usage for any anomalies. The researchers also advise users to avoid downloading pirated software from untrustworthy sources, which often contain hidden malware. They also advise that users enable automatic software updates, employ antivirus software, and continue to exercise caution when opening untrusted links.





