# Malicious NuGet Packages Disguised as Game Cheats Deploy Remote Access Malware (pepesoft.exe)

> Socket's Threat Research Team identified 11 malicious NuGet DotnetTool packages, all published by the account pepegit666, posing as cheats/bots/management panels for role-play games (Albion Online, GTA5RP, GrandRP, Majestic RP, Throne and Liberty, Lineage 2, RMRP, Russian Fishing 4). A two-stage chain — a shared .NET downloader abusing DNS-over-HTTPS and UAC elevation, then a PyInstaller/PyArmor-packed Python payload (pepesoft.exe) — provides remote screenshot access, hardware-bound licensing/HWID ban-listing, Google Sheets telemetry, Telegram-bot C2, Discord webhooks, and destructive file-wipe routines, attributed to the Russian-speaking commercial paid-cheat operator 'pepesoft' (storefront bots.pepesoft.ru).

- **Published:** 2026-07-15T00:00:00Z
- **Last reviewed:** 2026-07-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1352
- **ID:** TL-2026-1352
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 39 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On July 14, 2026, Socket's Threat Research Team (analyst Kush Pandya) published research on 11 malicious NuGet packages, all of the `DotnetTool` package type and all published under the single account `pepegit666`: albion-x-x, amazing-x-x, calc-x-x, grandrp-x-x, gta5rp-x-x, l2-x-x, majestic-x-x, rmrp-x-x, rusfish4-x-x, throne-x-x, and trigger-x-x. Each masquerades as a cheat, bot, or server-management panel for a specific Russian-speaking role-play (RP) gaming community — Albion Online, an unrelated 'Amazing RP', GTA5RP, GrandRP, Lineage 2, Majestic RP, RMRP, Russian Fishing 4, and Throne and Liberty — installed by victims via `dotnet tool install`.

All 11 packages share an identical first-stage .NET downloader assembly (albion.dll, amazingrp.dll, calculator.dll, grandrp.dll, gta5rp.dll, lineage2.dll, majestic.dll, rmrp.dll, rusfish4.dll, setup.dll, trigger.dll — each with a unique but structurally identical SHA-256). Ten of the eleven downloaders spawn a hidden PowerShell process using the `runas` verb to start the Windows Time service and force a clock resync, which functions as a pretext for UAC elevation. All downloaders use a custom `SocketsHttpHandler` with a `ConnectCallback` that resolves GitHub hosts through `dns.google/resolve` (DNS-over-HTTPS), bypassing local hosts-file and DNS-sinkhole blocking. All 11 share an identical hardcoded AWS-style access key/secret key pair and an identical process-mutex GUID (`Global\{5BD61028-3D9C-4B4E-AD45-CA4F1B35D0F4}`, derived from the same key material) that prints the Russian message 'Программа уже запущена' ('The program is already running') on re-invocation — conclusive evidence of a single shared build pipeline and operator.

Second-stage payload retrieval is multi-tiered: primary distribution via a Hugging Face bucket mirror (`huggingface.co/buckets/pepegit666/<tag>/resolve/pepesoft.exe`), fallback to GitHub Releases on the staging repo `github.com/pepegit666/123f53y45ysdf34` (tags per game: albion.onlinepanel, amazing.rp, calculator, grandrp.su, gta5rp.com, lineage2panel, majesticpanel, rmrp, russianfish4, throne, trigpanel), and a dormant BitTorrent magnet-link branch (MonoTorrent/Mono.Nat libraries bundled but inert in analyzed samples). Runtime configuration is retrieved from a Cloudflare Worker (`calm-voice-9797.888c888x888.workers.dev`), with an S3-compatible fallback store (`s3.ru-3.storage.selcloud.ru`, bucket `zfile`).

The resulting second-stage payload, pepesoft.exe, is PyInstaller-packed; 8 of 11 variants (Amazing RP, GrandRP, GTA5RP, Lineage 2, Majestic, RMRP, Russian Fishing 4, Trigger) are additionally protected with PyArmor and, embedded Python source is base64+zlib compressed and Fernet-encrypted, decoded and `exec()`'d at runtime. The remaining 3 variants (Albion, Calculator/'gtaobus.pyc', Throne) ship as unprotected direct Python bytecode modules. On execution, pepesoft.exe authenticates to a set of Google Sheets used as a telemetry and licensing backend: shared sheets `info`, `GTA5RP` (ban-list), and `STAT` (direct-bytecode telemetry), plus per-game product sheets (RMRP, AMAZING, GRANDRP, GTA5RP, L2, MajesticMAIN, RusFish4, TriggerRP, ALBIONBOTMAIN, GTA5RPCALC, THRONE). It records hardware fingerprints (CPU, motherboard, GPU model), hostname, IP-based geolocation, and OS activation status, then re-reads the stored spreadsheet row on subsequent launches and compares it to the live machine to enforce hardware-bound licensing. It also checks the host's HWID/UUID against a 'banned' worksheet; a match halts execution with the message 'Ваш ПК в системе приостановлен' ('Your PC is suspended in the system'), giving the operator a remote kill-switch. The 8 PyArmor-protected variants probe direct Google Sheets/googleapis.com access first and, on failure, retry the same traffic through a hardcoded authenticated HTTP proxy (`196.16.3.71:9528`, credentials `X1U0z7:ZHcUHN`) to bypass IP-level blocking.

For interactive access, the 3 direct-bytecode variants run an `aiogram`-based Telegram bot (channel `t.me/pepesoft777`, chat IDs cached locally in `./libgg/chat_ids.txt`) exposing commands `/screen`, `/pscreen`, `/connect`, and `/disconnect` that capture the active game window or full desktop via `pyautogui.screenshot()` and return images with `reply_photo` — enabling opportunistic capture of on-screen credentials, password managers, browser sessions, and cryptocurrency wallet interfaces. Two Discord webhook URLs are also embedded, providing a secondary exfiltration/notification channel. On exit, the direct-bytecode variants delete `DisableLogging` and `DisableMSI` values from `HKLM\Software\Policies\Microsoft\Windows\Installer` (weakening Windows Installer logging/policy controls) and, when a conditional flag (`exitadaptive`) is set, run a destructive cleanup batch that deletes every non-EXE file in the current directory, deletes `UnRaR.exe`, and recursively removes subdirectories — a routine that can destroy unrelated user files if the malware runs from a shared directory, and appears intended to erase forensic evidence.

Attribution indicators — the single publisher account `pepegit666`, Russian-language console/error strings, and consistent targeting of Russian-speaking RP gaming communities — point to a Russian-speaking commercial paid-cheat operator branding itself 'pepesoft', operating a public storefront at bots.pepesoft.ru. The campaign is financially motivated supply-chain-borne malvertising: gamers seeking paid cheats for competitive RP servers install what they believe is licensed cheat software and instead receive a fully featured remote access trojan with credential, financial-account, and privacy exposure risk. Socket reported the packages to the NuGet security team for takedown.

## MITRE ATT&CK

- T1584 Compromise Infrastructure
- T1587 Develop Capabilities
- T1583 Acquire Infrastructure
- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1112 Modify Registry
- T1548 Abuse Elevation Control Mechanism
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1112 Modify Registry
- T1070 Indicator Removal
- T1090 Proxy
- T1497 Virtualization/Sandbox Evasion
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1518 Software Discovery
- T1113 Screen Capture
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1102 Web Service
- T1090 Proxy
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1485 Data Destruction

## Sources

- [Fake Game Cheats NuGet Packages Deliver Remote Access Malware](https://cybersecuritynews.com/game-fake-cheats-remote-access/)
- [11 Malicious NuGet Tools Pose as Game Cheats](https://socket.dev/blog/11-malicious-nuget-tools-pose-as-game-cheats)
- [Malicious NuGet Packages Target Browser Credentials](https://cybersecuritynews.com/malicious-nuget-packages-target-browser-credentials/)
- [Windows User Account Control Bypassed](https://cybersecuritynews.com/windows-user-account-control-bypassed/)
- [NuGet Gallery — affected package registry](https://www.nuget.org/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1352
