🚨 Fake download links on itch.io!
So for those who haven't stumbled across them, there's currently a wave of spam claiming to have an "updated version" of many free #NSFWGames that is some form of malware.
The delivery method is via url-shortened catbox.moe links which then instruct the user to paste in a random URL (typically a direct file download).
The resulting .zip contains ~450+ files with all kinds of extensions, including a few bogus ones, and a file named Launcher.exe which likely launches the malware.
Based on HybridAnalysis and VirusTotal's Sandbox, the Launcher.exe tries to inject a bunch of pre-launch options into msedge.exe as well as utilizing obfuscation techniques such as cryptographic encryption via OpenSSL key as well as calling its own memory addresses. It also calls another catbox.moe address.
AhnLabV3 identifies it as Win32.Generic. While there appears to be nothing outright malicious about the file, it is incredibly suspicious, and is likely a dropper for something else
#Itchio #InfoSec #Malware #Games #VideoGames #NSFWGames #FurryGames #Gaming