Friday, March 1, 2024

Legion Tool Steals PUBG Players’ Browser Passwords through a Fake GitHub Repo

“The Legion” is a Python-based software that has been crafted with the explicit intention of gathering credentials.

Its propagation initially occurred via Telegram channels, where it was advertised as a tool that could be used for hacking.

The tool is well-known for its ability to steal users’ login credentials from a wide variety of services.

Researchers from Cyble uncovered a GitHub page that mimics a PUBG hack but downloads the stealer malware.

PUBG Hack as Malware

Players are tempted to download the hack as it helps them to gain an unfair advantage over other players.

These bypass hacks are designed in the way to bypass the game’s security measures and anti-cheat systems and help them to enable various cheats and hacks.

Below is the fake page that mimics a Pubg Bypass hack.

Fake Github page

The downloaded zip file drops various files, including “source code (.cs), project (.csproj), solution (.sln), icon (.ico), resources (.resources), and other supporting files like app.config, desktop.ini, and Readme.md.”

A file name “Karogour_BypasrcS.sln,” upon execution, drops “Local_ycsNYnaBZ(.)sln” and “LocalchfRgyVJSk(.)exe”.

The “Local_ycsNYnaBZ.sln” file opens the Visual Studio editor to trick the user; in the meantime, LocalchfRgyVJSk(.)exe got executed in the backend, and the executable is Legion Stealer.

Legion Stealer

The stealer “executes a series of commands, which include manipulating Windows Defender settings, extracting information from the registry, and gathering system details,” read the report.

The stealer gathers system information such as computer name, OS name, RAM size, UUID, CPU details, GPU details, and product key.

Also, other information such as IP address, region, country, time zone, cellular data connectivity, proxy/VPN usage, and reverse DNS.

The stealer also targets Crypto wallets and steals passwords from browsers, namely Brave, Chrome, Chromium, Comodo Dragon, Edge, Epic Privacy, Iridium, Opera, Opera GX, Slimjet, UR Browser, Vivaldi, and Yandex.

The stealer generates an overview of the stolen data and compresses the folder, and exfiltrates it to the Discord servers.

“AI-based email security measures Protect your business From Email Threats!” – Request a Free Demo.

Website

Latest articles

CWE Version 4.14 Released: What’s New!

The Common Weakness Enumeration (CWE) project, a cornerstone in the cybersecurity landscape, has unveiled...

RisePro Stealer Attacks Windows Users Steals Sensitive Data

A new wave of cyber threats has emerged as the RisePro information stealer targets...

Golden Corral restaurant chain Hacked: 180,000+ Users’ Data Stolen

The Golden Corral Corporation, a popular American restaurant chain, has suffered a significant data...

CISA Warns Of Hackers Exploiting Multiple Flaws In Ivanti VPN

Threat actors target and abuse VPN flaws because VPNs are often used to secure...

BEAST AI Jailbreak Language Models Within 1 Minute With High Accuracy

Malicious hackers sometimes jailbreak language models (LMs) to exploit bugs in the systems so...

Hackers Hijack Anycubic 3D Printers to Display Warning Messages

Anycubic 3D printer owners have been caught off guard by a series of unauthorized...

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

Stellar Cyber, the innovator of Open XDR, today announced that RSM US – the leading provider...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Live Account Takeover Attack Simulation

Live Account Take Over Attack

Live Webinar on How do hackers bypass 2FA ,Detecting ATO attacks, A demo of credential stuffing, brute force and session jacking-based ATO attacks, Identifying attacks with behaviour-based analysis and Building custom protection for applications and APIs.

Related Articles