Threat reportSupply ChainTL-2026-1352

Malicious NuGet Packages Disguised as Game Cheats Deploy Remote Access Malware (pepesoft.exe)

criticalACTIVE

Malicious NuGet Packages Disguised as Game Cheats Deploy (TL-2026-1352), also tracked as pepesoft campaign, is a critical-severity supply-chain compromise, first published 2026-07-15. It is linked to a Russia-nexus actor with medium confidence, affects NuGet Gallery NuGet DotnetTool packages published by pepegit666, maps to 26 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 39 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
26MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
39Indicators of compromise

Key facts for TL-2026-1352

Threat ID
TL-2026-1352
Also known as
pepesoft campaign, Fake Game Cheats NuGet Campaign, 11 Malicious NuGet Tools Pose as Game Cheats
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
gaming, individual consumers, software supply chain
Target regions
Global, russia, CIS / Russian-speaking gaming communities
Detection rules
9
Indicators of compromise
39

Malware and tooling in Malicious NuGet Packages Disguised as Game Cheats Deploy

Malware and tooling: pepesoft RAT, pepesoft.exe, Google Sheets (abused as telemetry/licensing/C2 channel), PyArmor, PyInstaller, Telegram Bot API (aiogram) — t.me/pepesoft777, aiogram

How Malicious NuGet Packages Disguised as Game Cheats Deploy works

Socket's Threat Research Team identified 11 malicious NuGet DotnetTool packages, all published by the account pepegit666, posing as cheats/bots/management panels for role-play games (Albion Online, GTA5RP, GrandRP, Majestic RP, Throne and Liberty, Lineage 2, RMRP, Russian Fishing 4). A two-stage chain — a shared .NET downloader abusing DNS-over-HTTPS and UAC elevation, then a PyInstaller/PyArmor-packed Python payload (pepesoft.exe) — provides remote screenshot access, hardware-bound licensing/HWID ban-listing, Google Sheets telemetry, Telegram-bot C2, Discord webhooks, and destructive file-wipe routines, attributed to the Russian-speaking commercial paid-cheat operator 'pepesoft' (storefront bots.pepesoft.ru).

On July 14, 2026, Socket's Threat Research Team (analyst Kush Pandya) published research on 11 malicious NuGet packages, all of the `DotnetTool` package type and all published under the single account `pepegit666`: albion-x-x, amazing-x-x, calc-x-x, grandrp-x-x, gta5rp-x-x, l2-x-x, majestic-x-x, rmrp-x-x, rusfish4-x-x, throne-x-x, and trigger-x-x. Each masquerades as a cheat, bot, or server-management panel for a specific Russian-speaking role-play (RP) gaming community — Albion Online, an unrelated 'Amazing RP', GTA5RP, GrandRP, Lineage 2, Majestic RP, RMRP, Russian Fishing 4, and Throne and Liberty — installed by victims via `dotnet tool install`.

All 11 packages share an identical first-stage .NET downloader assembly (albion.dll, amazingrp.dll, calculator.dll, grandrp.dll, gta5rp.dll, lineage2.dll, majestic.dll, rmrp.dll, rusfish4.dll, setup.dll, trigger.dll — each with a unique but structurally identical SHA-256). Ten of the eleven downloaders spawn a hidden PowerShell process using the `runas` verb to start the Windows Time service and force a clock resync, which functions as a pretext for UAC elevation. All downloaders use a custom `SocketsHttpHandler` with a `ConnectCallback` that resolves GitHub hosts through `dns.google/resolve` (DNS-over-HTTPS), bypassing local hosts-file and DNS-sinkhole blocking. All 11 share an identical hardcoded AWS-style access key/secret key pair and an identical process-mutex GUID (`Global\{5BD61028-3D9C-4B4E-AD45-CA4F1B35D0F4}`, derived from the same key material) that prints the Russian message 'Программа уже запущена' ('The program is already running') on re-invocation — conclusive evidence of a single shared build pipeline and operator.

Second-stage payload retrieval is multi-tiered: primary distribution via a Hugging Face bucket mirror (`huggingface.co/buckets/pepegit666/<tag>/resolve/pepesoft.exe`), fallback to GitHub Releases on the staging repo `github.com/pepegit666/123f53y45ysdf34` (tags per game: albion.onlinepanel, amazing.rp, calculator, grandrp.su, gta5rp.com, lineage2panel, majesticpanel, rmrp, russianfish4, throne, trigpanel), and a dormant BitTorrent magnet-link branch (MonoTorrent/Mono.Nat libraries bundled but inert in analyzed samples). Runtime configuration is retrieved from a Cloudflare Worker (`calm-voice-9797.888c888x888.workers.dev`), with an S3-compatible fallback store (`s3.ru-3.storage.selcloud.ru`, bucket `zfile`).

The resulting second-stage payload, pepesoft.exe, is PyInstaller-packed; 8 of 11 variants (Amazing RP, GrandRP, GTA5RP, Lineage 2, Majestic, RMRP, Russian Fishing 4, Trigger) are additionally protected with PyArmor and, embedded Python source is base64+zlib compressed and Fernet-encrypted, decoded and `exec()`'d at runtime. The remaining 3 variants (Albion, Calculator/'gtaobus.pyc', Throne) ship as unprotected direct Python bytecode modules. On execution, pepesoft.exe authenticates to a set of Google Sheets used as a telemetry and licensing backend: shared sheets `info`, `GTA5RP` (ban-list), and `STAT` (direct-bytecode telemetry), plus per-game product sheets (RMRP, AMAZING, GRANDRP, GTA5RP, L2, MajesticMAIN, RusFish4, TriggerRP, ALBIONBOTMAIN, GTA5RPCALC, THRONE). It records hardware fingerprints (CPU, motherboard, GPU model), hostname, IP-based geolocation, and OS activation status, then re-reads the stored spreadsheet row on subsequent launches and compares it to the live machine to enforce hardware-bound licensing. It also checks the host's HWID/UUID against a 'banned' worksheet; a match halts execution with the message 'Ваш ПК в системе приостановлен' ('Your PC is suspended in the system'), giving the operator a remote kill-switch. The 8 PyArmor-protected variants probe direct Google Sheets/googleapis.com access first and, on failure, retry the same traffic through a hardcoded authenticated HTTP proxy (`196.16.3.71:9528`, credentials `X1U0z7:ZHcUHN`) to bypass IP-level blocking.

For interactive access, the 3 direct-bytecode variants run an `aiogram`-based Telegram bot (channel `t.me/pepesoft777`, chat IDs cached locally in `./libgg/chat_ids.txt`) exposing commands `/screen`, `/pscreen`, `/connect`, and `/disconnect` that capture the active game window or full desktop via `pyautogui.screenshot()` and return images with `reply_photo` — enabling opportunistic capture of on-screen credentials, password managers, browser sessions, and cryptocurrency wallet interfaces. Two Discord webhook URLs are also embedded, providing a secondary exfiltration/notification channel. On exit, the direct-bytecode variants delete `DisableLogging` and `DisableMSI` values from `HKLM\Software\Policies\Microsoft\Windows\Installer` (weakening Windows Installer logging/policy controls) and, when a conditional flag (`exitadaptive`) is set, run a destructive cleanup batch that deletes every non-EXE file in the current directory, deletes `UnRaR.exe`, and recursively removes subdirectories — a routine that can destroy unrelated user files if the malware runs from a shared directory, and appears intended to erase forensic evidence.

Attribution indicators — the single publisher account `pepegit666`, Russian-language console/error strings, and consistent targeting of Russian-speaking RP gaming communities — point to a Russian-speaking commercial paid-cheat operator branding itself 'pepesoft', operating a public storefront at bots.pepesoft.ru. The campaign is financially motivated supply-chain-borne malvertising: gamers seeking paid cheats for competitive RP servers install what they believe is licensed cheat software and instead receive a fully featured remote access trojan with credential, financial-account, and privacy exposure risk. Socket reported the packages to the NuGet security team for takedown.

MITRE ATT&CK techniques used in TL-2026-1352

Collection

T1005 Data from Local System; T1113 Screen Capture

Discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1518 Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer

command-and-control

T1090 Proxy

Persistence

T1112 Modify Registry; T1547 Boot or Logon Autostart Execution

defense-impairment

T1112 Modify Registry

Initial Access

T1195 Supply Chain Compromise; T1199 Trusted Relationship

Impact

T1485 Data Destruction

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities

Affected products and versions in Malicious NuGet Packages Disguised as Game Cheats Deploy

  • NuGet Gallery — NuGet DotnetTool packages published by pepegit666 (albion-x-x, amazing-x-x, calc-x-x, grandrp-x-x, gta5rp-x-x, l2-x-x, majestic-x-x, rmrp-x-x, rusfish4-x-x, throne-x-x, trigger-x-x)
    Vulnerable versions: all published versions of the 11 identified packages
    Fixed in: N/A — packages reported to NuGet security team for takedown
  • pepesoft — pepesoft.exe (PyInstaller/PyArmor-packed second-stage payload)
    Vulnerable versions: all observed builds across 11 game-specific variants

Remediation for Malicious NuGet Packages Disguised as Game Cheats Deploy

Immediate actions

  • Remove all 11 identified malicious NuGet DotnetTool packages (albion-x-x, amazing-x-x, calc-x-x, grandrp-x-x, gta5rp-x-x, l2-x-x, majestic-x-x, rmrp-x-x, rusfish4-x-x, throne-x-x, trigger-x-x) from developer and gamer machines
  • Kill and quarantine any running pepesoft.exe process; treat the host as compromised and image for forensics before any cleanup routine can trigger destructive file deletion
  • Block egress to bots.pepesoft.ru, calm-voice-9797.888c888x888.workers.dev, s3.ru-3.storage.selcloud.ru, 196.16.3.71:9528, and t.me/pepesoft777 at the perimeter and via DNS/web filtering
  • Rotate any credentials (password manager, browser session, crypto wallet) that were visible on-screen while the host was infected
  • Block outbound Telegram Bot API and Discord webhook traffic (api.telegram.org, discord.com/api/webhooks) from developer workstations where not business-justified
  • Audit HKLM\Software\Policies\Microsoft\Windows\Installer for tampered DisableLogging/DisableMSI values on any host that ran the direct-bytecode variants
  • Restrict or monitor DNS-over-HTTPS usage (dns.google/resolve and similar) from endpoints to detect DoH-based sinkhole evasion

Workarounds

  • Disable `dotnet tool install` from untrusted/public NuGet sources on managed endpoints
  • Block DNS-over-HTTPS resolvers at the network layer to force DNS resolution through monitored/sinkholed resolvers

Longer-term hardening

  • Deploy software composition analysis / package-registry scanning (e.g., Socket) in CI and on developer workstations to flag malicious npm/NuGet/PyPI installs before execution
  • Enforce a policy prohibiting installation of unofficial 'cheat', 'bot', or 'management panel' tools for third-party games on corporate or personal-with-VPN-access endpoints
  • Deploy EDR with behavioral detection for PyInstaller-packed/PyArmor-obfuscated child processes spawned from dotnet tool executables
  • Monitor for anomalous Google Sheets API traffic (accounts.google.com/googleapis.com from unexpected processes) and Hugging Face bucket downloads of executables

Weaknesses (CWE) in Malicious NuGet Packages Disguised as Game Cheats Deploy

CWE-506, CWE-494, CWE-522, CWE-798

Timeline of Malicious NuGet Packages Disguised as Game Cheats Deploy

  • Estimated active window for the 11 malicious NuGet DotnetTool packages published by pepegit666 prior to public disclosure; exact publication dates of individual packages not specified by the source.
  • Socket publishes '11 Malicious NuGet Tools Pose as Game Cheats' at socket.dev/blog with full technical IOC breakdown.
  • Socket reports the identified malicious packages to the NuGet security team for remediation/takedown.
  • Socket's Threat Research Team (Kush Pandya) identifies and analyzes the 11 malicious NuGet packages disguised as game cheats/bots/management panels for RP gaming communities, extracting hashes, hardcoded credentials, and full C2 infrastructure.
  • Threat first observed/ingested by the Threadlinqs Intelligence Platform hunt pipeline via RSS source feed.
  • Socket's disclosure and derivative reporting circulate remediation guidance for defenders — perimeter blocking of identified C2/hosting infrastructure, credential rotation, and Windows Installer policy audits — following the public disclosure.
  • Cyber Security News publishes companion coverage 'Windows User Account Control Bypassed', detailing the same campaign's hidden-PowerShell/runas UAC elevation technique used by 10 of the 11 first-stage downloaders.
  • Cyber Security News publishes companion coverage 'Malicious NuGet Packages Target Browser Credentials', contextualizing the pepesoft campaign within a broader wave of credential-focused malicious NuGet packages.
  • Cyber Security News publishes 'Fake Game Cheats NuGet Packages Deliver Remote Access Malware', summarizing Socket's findings for a broader audience.

Sources cited for Malicious NuGet Packages Disguised as Game Cheats Deploy

Detection coverage for TL-2026-1352

As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1352 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
39 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats