Last Updated: 2026-07-20T16:00:07Z
What’s Happening
Malwarebytes is reporting on a new infostealer campaign using pirated games (shocker) as a watering hole.
What’s notable about this campaign is the continued use of Etherhiding for second-stage loading. We’re going to be talking a lot about Etherhiding in the next couple of weeks.
Some other fun malware analysis in the post as well for those interested.
Actions
Don’t pirate games! Don’t let your employees pirate games! Pro tip: if you do VPN posture checks, disallowing Steam is a gigantic risk reducer.
Otherwise, review the IOCs in the Malwarebytes post. We’re adding them to our MISP as well.