Threat reportSupply ChainTL-2026-1352
Malicious NuGet Packages Disguised as Game Cheats Deploy Remote Access Malware (pepesoft.exe)
Malicious NuGet Packages Disguised as Game Cheats Deploy (TL-2026-1352), also tracked as pepesoft campaign, is a critical-severity supply-chain compromise, first published 2026-07-15. It is linked to a Russia-nexus actor with medium confidence, affects NuGet Gallery NuGet DotnetTool packages published by pepegit666, maps to 26 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 39 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 26MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 39Indicators of compromise
Key facts for TL-2026-1352
- Threat ID
- TL-2026-1352
- Also known as
- pepesoft campaign, Fake Game Cheats NuGet Campaign, 11 Malicious NuGet Tools Pose as Game Cheats
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- gaming, individual consumers, software supply chain
- Target regions
- Global, russia, CIS / Russian-speaking gaming communities
- Detection rules
- 9
- Indicators of compromise
- 39
Malware and tooling in Malicious NuGet Packages Disguised as Game Cheats Deploy
Malware and tooling: pepesoft RAT, pepesoft.exe, Google Sheets (abused as telemetry/licensing/C2 channel), PyArmor, PyInstaller, Telegram Bot API (aiogram) — t.me/pepesoft777, aiogram
How Malicious NuGet Packages Disguised as Game Cheats Deploy works
Socket's Threat Research Team identified 11 malicious NuGet DotnetTool packages, all published by the account pepegit666, posing as cheats/bots/management panels for role-play games (Albion Online, GTA5RP, GrandRP, Majestic RP, Throne and Liberty, Lineage 2, RMRP, Russian Fishing 4). A two-stage chain — a shared .NET downloader abusing DNS-over-HTTPS and UAC elevation, then a PyInstaller/PyArmor-packed Python payload (pepesoft.exe) — provides remote screenshot access, hardware-bound licensing/HWID ban-listing, Google Sheets telemetry, Telegram-bot C2, Discord webhooks, and destructive file-wipe routines, attributed to the Russian-speaking commercial paid-cheat operator 'pepesoft' (storefront bots.pepesoft.ru).
On July 14, 2026, Socket's Threat Research Team (analyst Kush Pandya) published research on 11 malicious NuGet packages, all of the `DotnetTool` package type and all published under the single account `pepegit666`: albion-x-x, amazing-x-x, calc-x-x, grandrp-x-x, gta5rp-x-x, l2-x-x, majestic-x-x, rmrp-x-x, rusfish4-x-x, throne-x-x, and trigger-x-x. Each masquerades as a cheat, bot, or server-management panel for a specific Russian-speaking role-play (RP) gaming community — Albion Online, an unrelated 'Amazing RP', GTA5RP, GrandRP, Lineage 2, Majestic RP, RMRP, Russian Fishing 4, and Throne and Liberty — installed by victims via `dotnet tool install`.
All 11 packages share an identical first-stage .NET downloader assembly (albion.dll, amazingrp.dll, calculator.dll, grandrp.dll, gta5rp.dll, lineage2.dll, majestic.dll, rmrp.dll, rusfish4.dll, setup.dll, trigger.dll — each with a unique but structurally identical SHA-256). Ten of the eleven downloaders spawn a hidden PowerShell process using the `runas` verb to start the Windows Time service and force a clock resync, which functions as a pretext for UAC elevation. All downloaders use a custom `SocketsHttpHandler` with a `ConnectCallback` that resolves GitHub hosts through `dns.google/resolve` (DNS-over-HTTPS), bypassing local hosts-file and DNS-sinkhole blocking. All 11 share an identical hardcoded AWS-style access key/secret key pair and an identical process-mutex GUID (`Global\{5BD61028-3D9C-4B4E-AD45-CA4F1B35D0F4}`, derived from the same key material) that prints the Russian message 'Программа уже запущена' ('The program is already running') on re-invocation — conclusive evidence of a single shared build pipeline and operator.
Second-stage payload retrieval is multi-tiered: primary distribution via a Hugging Face bucket mirror (`huggingface.co/buckets/pepegit666/<tag>/resolve/pepesoft.exe`), fallback to GitHub Releases on the staging repo `github.com/pepegit666/123f53y45ysdf34` (tags per game: albion.onlinepanel, amazing.rp, calculator, grandrp.su, gta5rp.com, lineage2panel, majesticpanel, rmrp, russianfish4, throne, trigpanel), and a dormant BitTorrent magnet-link branch (MonoTorrent/Mono.Nat libraries bundled but inert in analyzed samples). Runtime configuration is retrieved from a Cloudflare Worker (`calm-voice-9797.888c888x888.workers.dev`), with an S3-compatible fallback store (`s3.ru-3.storage.selcloud.ru`, bucket `zfile`).
The resulting second-stage payload, pepesoft.exe, is PyInstaller-packed; 8 of 11 variants (Amazing RP, GrandRP, GTA5RP, Lineage 2, Majestic, RMRP, Russian Fishing 4, Trigger) are additionally protected with PyArmor and, embedded Python source is base64+zlib compressed and Fernet-encrypted, decoded and `exec()`'d at runtime. The remaining 3 variants (Albion, Calculator/'gtaobus.pyc', Throne) ship as unprotected direct Python bytecode modules. On execution, pepesoft.exe authenticates to a set of Google Sheets used as a telemetry and licensing backend: shared sheets `info`, `GTA5RP` (ban-list), and `STAT` (direct-bytecode telemetry), plus per-game product sheets (RMRP, AMAZING, GRANDRP, GTA5RP, L2, MajesticMAIN, RusFish4, TriggerRP, ALBIONBOTMAIN, GTA5RPCALC, THRONE). It records hardware fingerprints (CPU, motherboard, GPU model), hostname, IP-based geolocation, and OS activation status, then re-reads the stored spreadsheet row on subsequent launches and compares it to the live machine to enforce hardware-bound licensing. It also checks the host's HWID/UUID against a 'banned' worksheet; a match halts execution with the message 'Ваш ПК в системе приостановлен' ('Your PC is suspended in the system'), giving the operator a remote kill-switch. The 8 PyArmor-protected variants probe direct Google Sheets/googleapis.com access first and, on failure, retry the same traffic through a hardcoded authenticated HTTP proxy (`196.16.3.71:9528`, credentials `X1U0z7:ZHcUHN`) to bypass IP-level blocking.
For interactive access, the 3 direct-bytecode variants run an `aiogram`-based Telegram bot (channel `t.me/pepesoft777`, chat IDs cached locally in `./libgg/chat_ids.txt`) exposing commands `/screen`, `/pscreen`, `/connect`, and `/disconnect` that capture the active game window or full desktop via `pyautogui.screenshot()` and return images with `reply_photo` — enabling opportunistic capture of on-screen credentials, password managers, browser sessions, and cryptocurrency wallet interfaces. Two Discord webhook URLs are also embedded, providing a secondary exfiltration/notification channel. On exit, the direct-bytecode variants delete `DisableLogging` and `DisableMSI` values from `HKLM\Software\Policies\Microsoft\Windows\Installer` (weakening Windows Installer logging/policy controls) and, when a conditional flag (`exitadaptive`) is set, run a destructive cleanup batch that deletes every non-EXE file in the current directory, deletes `UnRaR.exe`, and recursively removes subdirectories — a routine that can destroy unrelated user files if the malware runs from a shared directory, and appears intended to erase forensic evidence.
Attribution indicators — the single publisher account `pepegit666`, Russian-language console/error strings, and consistent targeting of Russian-speaking RP gaming communities — point to a Russian-speaking commercial paid-cheat operator branding itself 'pepesoft', operating a public storefront at bots.pepesoft.ru. The campaign is financially motivated supply-chain-borne malvertising: gamers seeking paid cheats for competitive RP servers install what they believe is licensed cheat software and instead receive a fully featured remote access trojan with credential, financial-account, and privacy exposure risk. Socket reported the packages to the NuGet security team for takedown.
MITRE ATT&CK techniques used in TL-2026-1352
Collection
T1005 Data from Local System; T1113 Screen Capture
Discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1518 Software Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer
command-and-control
Persistence
T1112 Modify Registry; T1547 Boot or Logon Autostart Execution
defense-impairment
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
Impact
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities
Affected products and versions in Malicious NuGet Packages Disguised as Game Cheats Deploy
- NuGet Gallery — NuGet DotnetTool packages published by pepegit666 (albion-x-x, amazing-x-x, calc-x-x, grandrp-x-x, gta5rp-x-x, l2-x-x, majestic-x-x, rmrp-x-x, rusfish4-x-x, throne-x-x, trigger-x-x)
Vulnerable versions: all published versions of the 11 identified packages
Fixed in: N/A — packages reported to NuGet security team for takedown - pepesoft — pepesoft.exe (PyInstaller/PyArmor-packed second-stage payload)
Vulnerable versions: all observed builds across 11 game-specific variants
Remediation for Malicious NuGet Packages Disguised as Game Cheats Deploy
Immediate actions
- Remove all 11 identified malicious NuGet DotnetTool packages (albion-x-x, amazing-x-x, calc-x-x, grandrp-x-x, gta5rp-x-x, l2-x-x, majestic-x-x, rmrp-x-x, rusfish4-x-x, throne-x-x, trigger-x-x) from developer and gamer machines
- Kill and quarantine any running pepesoft.exe process; treat the host as compromised and image for forensics before any cleanup routine can trigger destructive file deletion
- Block egress to bots.pepesoft.ru, calm-voice-9797.888c888x888.workers.dev, s3.ru-3.storage.selcloud.ru, 196.16.3.71:9528, and t.me/pepesoft777 at the perimeter and via DNS/web filtering
- Rotate any credentials (password manager, browser session, crypto wallet) that were visible on-screen while the host was infected
- Block outbound Telegram Bot API and Discord webhook traffic (api.telegram.org, discord.com/api/webhooks) from developer workstations where not business-justified
- Audit HKLM\Software\Policies\Microsoft\Windows\Installer for tampered DisableLogging/DisableMSI values on any host that ran the direct-bytecode variants
- Restrict or monitor DNS-over-HTTPS usage (dns.google/resolve and similar) from endpoints to detect DoH-based sinkhole evasion
Workarounds
- Disable `dotnet tool install` from untrusted/public NuGet sources on managed endpoints
- Block DNS-over-HTTPS resolvers at the network layer to force DNS resolution through monitored/sinkholed resolvers
Longer-term hardening
- Deploy software composition analysis / package-registry scanning (e.g., Socket) in CI and on developer workstations to flag malicious npm/NuGet/PyPI installs before execution
- Enforce a policy prohibiting installation of unofficial 'cheat', 'bot', or 'management panel' tools for third-party games on corporate or personal-with-VPN-access endpoints
- Deploy EDR with behavioral detection for PyInstaller-packed/PyArmor-obfuscated child processes spawned from dotnet tool executables
- Monitor for anomalous Google Sheets API traffic (accounts.google.com/googleapis.com from unexpected processes) and Hugging Face bucket downloads of executables
Weaknesses (CWE) in Malicious NuGet Packages Disguised as Game Cheats Deploy
Timeline of Malicious NuGet Packages Disguised as Game Cheats Deploy
- Estimated active window for the 11 malicious NuGet DotnetTool packages published by pepegit666 prior to public disclosure; exact publication dates of individual packages not specified by the source.
- Socket publishes '11 Malicious NuGet Tools Pose as Game Cheats' at socket.dev/blog with full technical IOC breakdown.
- Socket reports the identified malicious packages to the NuGet security team for remediation/takedown.
- Socket's Threat Research Team (Kush Pandya) identifies and analyzes the 11 malicious NuGet packages disguised as game cheats/bots/management panels for RP gaming communities, extracting hashes, hardcoded credentials, and full C2 infrastructure.
- Threat first observed/ingested by the Threadlinqs Intelligence Platform hunt pipeline via RSS source feed.
- Socket's disclosure and derivative reporting circulate remediation guidance for defenders — perimeter blocking of identified C2/hosting infrastructure, credential rotation, and Windows Installer policy audits — following the public disclosure.
- Cyber Security News publishes companion coverage 'Windows User Account Control Bypassed', detailing the same campaign's hidden-PowerShell/runas UAC elevation technique used by 10 of the 11 first-stage downloaders.
- Cyber Security News publishes companion coverage 'Malicious NuGet Packages Target Browser Credentials', contextualizing the pepesoft campaign within a broader wave of credential-focused malicious NuGet packages.
- Cyber Security News publishes 'Fake Game Cheats NuGet Packages Deliver Remote Access Malware', summarizing Socket's findings for a broader audience.
Sources cited for Malicious NuGet Packages Disguised as Game Cheats Deploy
Detection coverage for TL-2026-1352
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1352 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.