Pepesoft

discovered 2026-07-14

Commercial paid game-cheat operation run under the "Pepesoft" brand (operator username pepegit666, storefront bots.pepesoft[.]ru, Telegram t[.]me/pepesoft777). Eleven NuGet DotnetTool downloaders posing as game cheats/tools each fetch a shared PyInstaller second-stage (pepesoft.exe) that performs Windows host surveillance. Single toolchain: all 11 share the same AWS-style key material and process-mutex GUID. Uses Google Sheets for host telemetry/licensing, hardware-fingerprint binding, a server-side HWID/UUID ban-list kill switch, and (in 3 direct-bytecode builds) Telegram screenshot remote-control. Russian-speaking operator/audience (language, .su/.ru staging, Selectel S3, Russian RP game targets) recorded as a language/targeting signal, NOT a nationality or state-affiliation claim.

Objective

Distribute a Windows host-surveillance payload as a paid game-cheat service with Sheets-based telemetry/licensing and a remote HWID kill switch.

Packages

Indicators

Techniques

Read the full analysis →