216.73.216.6

Distribution of SmartLoader Malware via Github Repository Disguised as a Legitimate Project

· Published 13/08/2025 15:43 · Modified 13/08/2025 15:48

Export JSON

Essential information

Published
13/08/2025 15:43
Modified
13/08/2025 15:48
Tags
2025-08-13 c2 game cheats github infostealer luascript lumma stealer obfuscation persistence redline rhadamanthys smartloader software-cracks
Related entities
11 observables, 14 techniques (mitre), 4 malware

Description

A massive distribution of malware has been discovered through repositories masquerading as legitimate projects. These repositories focus on topics like , software cracks, and automation tools to attract users. The malware is distributed via compressed files containing a legitimate Lua loader executable, a malicious batch file, and an obfuscated Lua script. Once executed, establishes , sends system information to a server, and downloads additional payloads. The malware has been observed downloading malware such as , , and . Users are advised to download software only from official sources and to carefully verify the credibility of repositories before use.

External references