malware nuget

albion-x-x

discovered 2026-07-14

NuGet DotnetTool downloader ("Albion Online") published under operator pepegit666. Assembly albion.dll, release tag "albion.onlinepanel". Ships gtaobus.pyc as DIRECT bytecode (Python 3.13) and adds an aiogram Telegram remote-control surface (screenshot/OCR, 36 unauthenticated handlers). On run it masquerades with a colored Russian console, sets AWS-style env vars, DoH-resolves GitHub hosts, and fetches the shared second-stage pepesoft.exe (Hugging Face -> GitHub Releases -> dormant BitTorrent). The payload writes host telemetry/inventory to Google Sheets and enforces an HWID/UUID ban-list kill switch. Only the [email protected] version was explicitly disclosed; other package versions were not enumerated in the source.

Threat types

data_exfiltration c2_agent rat

Malicious versions

  • unspecified

Campaigns

Indicators

Techniques

Read the full analysis →