Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: Medium
Victim: Digitain
Incident: Typosquatting attack via a trojanized NuGet package to rig online betting games.
Impact: Unauthorized manipulation of game results and exfiltration of betting data.
Attacker: Unidentified threat actors
Analysis: Threat actors published a trojanized fork of a popular JSON library to specifically target Digitain’s game backend. The malware remains dormant for most users, activating only when specific backend methods are present to avoid detection. The campaign evolved through three generations of payloads, increasing in obfuscation and exfiltration stability.
Recommendations: Pin NuGet dependencies to known-good versions using packages.lock.json; Audit project dependencies for the typosquatted package Newtonsoftt.Json.Net; Block egress traffic to the C2 IP 185.126.237[.]64
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source