Commercial paid game-cheat operation run under the "Pepesoft" brand (operator username pepegit666, storefront bots.pepesoft[.]ru, Telegram t[.]me/pepesoft777). Eleven NuGet DotnetTool downloaders posing as game cheats/tools each fetch a shared PyInstaller second-stage (pepesoft.exe) that performs Windows host surveillance. Single toolchain: all 11 share the same AWS-style key material and process-mutex GUID. Uses Google Sheets for host telemetry/licensing, hardware-fingerprint binding, a server-side HWID/UUID ban-list kill switch, and (in 3 direct-bytecode builds) Telegram screenshot remote-control. Russian-speaking operator/audience (language, .su/.ru staging, Selectel S3, Russian RP game targets) recorded as a language/targeting signal, NOT a nationality or state-affiliation claim.
Objective
Distribute a Windows host-surveillance payload as a paid game-cheat service with Sheets-based telemetry/licensing and a remote HWID kill switch.
Packages
- nuget albion-x-xattributed-to
- nuget amazing-x-xattributed-to
- nuget calc-x-xattributed-to
- nuget grandrp-x-xattributed-to
- nuget gta5rp-x-xattributed-to
- nuget l2-x-xattributed-to
- nuget majestic-x-xattributed-to
- nuget rmrp-x-xattributed-to
- nuget rusfish4-x-xattributed-to
- nuget throne-x-xattributed-to
- nuget trigger-x-xattributed-to
Indicators
- github_repo github.com/pepegit666/123f53y45ysdf34communicates-with
- domain calm-voice-9797.888c888x888.workers.devcommunicates-with
- domain s3.ru-3.storage.selcloud.rucommunicates-with
- domain bots.pepesoft.ruuses
- domain dns.googlecommunicates-with
- url https://github.com/pepegit666/123f53y45ysdf34/releases/download/<tag>/pepesoft.execommunicates-with
- url https://huggingface.co/buckets/pepegit666/<tag>/resolve/pepesoft.exe?download=truecommunicates-with
- ipv4 196.16.3.71communicates-with
- telegram_bot t.me/pepesoft777uses
- discord_webhook discord.com/api/webhooks/1156474517871403078/zuHl6xQzdMcFjNrmm9jTiHvCzNbCiQhkYAIGWNUfj7X4KUIpEATekKlSNna6OvyCKaRwcommunicates-with
- discord_webhook discord.com/api/webhooks/1156474527874818088/qS5cJuxEbyIA1s3tZX_A2u6YsKtLUARVPvN77_6fK5QHGdGFHb3JSuCUSDhtouEsyJgkcommunicates-with
- file_path ./libgg/chat_ids.txtuses
- file_path %LOCALAPPDATA%\Windows Src\key*.txtuses
- file_path ./token.txtuses
- file_path credentials.txtuses
- file_path %APPDATA%\pepesoftuses
- file_path pepesoft.exeuses
- sha256 d5385526f2f3e52c7d96087611c6cd4e479bf61828400efdb3ca09406d981609indicates
- sha256 567952daf0ab7b36b017aac9963791188dea0fbf2e99c7cc6f6652ee540f4840drops
- sha256 9a2091e6625fc11cfd8f39c17aa271604e66322ee045028946274b988103e35bindicates
- sha256 774e40046f353e3f916f39e3d13d6499da35705a479cfb89288c21017aaf5461drops
- sha256 e8c2618565aa31d7ffe909ebc99040bafcc0ea8df7f5d92fa673bb7ffacb14c9drops
- sha256 900ddb81d27e03967209fee4d17d13deb68eef0e1f10936eb520ca10575cb49eindicates
- sha256 cc853b3e4504c890d275ac2327f18acd7e4c5b99ca056181f3f5694781f2cf45drops
- sha256 ab58a90eb3682c6dc3389cd700a64f68a19c0dac3d0fa8e3df97ae041f96d4e1indicates
- sha256 23e4d8af5425dae022793450190c8d30809b2986dd879eb4bff557cdacf49c86drops
- sha256 6eefe9d5f030d403c72bd4e4caf5bbb9dbc2bd5e15ebb07de153494f458e5eb9drops
- sha256 e6e1049158ceb1971c61388349c81fa6047a7aecb4ff2089ef54a50dcc35dbc0indicates
- sha256 95577498d23fe750221a5badfc25b5e9f020dcf4d80c79a019b090e3c3b0a32adrops
- sha256 8ab256dd839aec6638cd46374f4a6664e534b9341bbcdfd9b763e5a27c51ddb7drops
- sha256 d9f7ca9f93a7d188d51db308877b15d0beae932ca0bf4705384fbedf54b454c1indicates
- sha256 2a4fed04d792b9c2fdf9c1456a08ca23eda5fef50c0b409ab294ad489e12d801drops
- sha256 6c1f828e4d8395dde8293868c65ba8d86b3b9672ebbbb16e932624706d37d832drops
- sha256 4d13f1136b13c871c65141b77ec7208488334ac4be511800196adcd328666305indicates
- sha256 7e42d25e707d29d5d185a4c5dc71019f744e88a30b66bbf06949194ff32dbc48drops
- sha256 6cbd4bc491deb11040e2b2f91b0b4e129af551a802fc78cb42e0e985297ef44cdrops
- sha256 011926de3d0cc2b970627b9bf0de003e731f8576602dff756d2ab54a9de61972indicates
- sha256 d59e1914d76499fa51bf861f418c84bda0b48913dc39bd2e73756e326e4ccbb0drops
- sha256 5d9843126db4223dc2a8a9cd4a627286fe1a6345e33b28e9c98b5fe56fe89da6drops
- sha256 79c09e1ffb4804c14ff27d41ec08d4390455c92d65717be0aeeec2697297d76aindicates
- sha256 17b1d836c2f15a97be0350879943b04e14bc076cf09e31df0d73258ee10f7e7cdrops
- sha256 c9f3e7766dbe728d84a1243447faa5f5eba0645bf13089074d128ea7663e7f5bdrops
- sha256 5f3a9ebf7039097b3cdbca8609b5b68af07eeb1dbf716ba2817a97fc7c543854indicates
- sha256 476c6f36a22156e53548a87291989a21d6c905dcbd9e1bf68ff5bc12e5c8bb07drops
- sha256 23808e7638f7a00b1ef9b9f4ca524f8a46cf63be6f6b79fec8e4a3fd1cc82a1eindicates
- sha256 01d2afea0f2201a3b59765a1a60ba324ff4b8fdd25f23a0e05824b97f195b27cdrops
- sha256 a2a5e473dba85959b21b7e8a184bc255d5f2dacdf7411b91d212fb1217d2518bdrops
Techniques
- ttp T1195.002 Compromise Software Supply Chainuses
- ttp T1608.001 Stage Capabilities: Upload Malwareuses
- ttp T1105 Ingress Tool Transferuses
- ttp T1140 Deobfuscate/Decode Files or Informationuses
- ttp T1027.002 Obfuscated Files or Information: Software Packinguses
- ttp T1071.001 Application Layer Protocol: Web Protocolsuses
- ttp T1059.001 Command and Scripting Interpreter: PowerShelluses
- ttp T1059.003 Command and Scripting Interpreter: Windows Command Shelluses
- ttp T1113 Screen Captureuses
- ttp T1082 System Information Discoveryuses
- ttp T1057 Process Discoveryuses
- ttp T1016 System Network Configuration Discoveryuses
- ttp T1567 Exfiltration Over Web Serviceuses
- ttp T1090.002 Proxy: External Proxyuses
- ttp T1112 Modify Registryuses
- ttp T1070.004 File Deletionuses