MALICIOUS (1) campaign cataloged at 2026-09-03(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-09-uvhttp-custom¶
During installation, obfuscated code downloads and executes an executable. It appears to be a game launcher.
Abuse categories¶
obfuscation
Code uses obfuscation techniques to hide its true purpose.
override_install
The package overrides the install command in setup.py to execute malicious code during installation.
remote_executable
Downloads and executes a remote executable.
References¶
Referenced resources may include blog posts about the campaign, malware analysis, sandbox reports, or other relevant information.
IoCs & related URLs¶
URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.
hxxps://cdn.discordapp.com/attachments/1532996358427115552/1539384056284717066/enlisted_launcher_1.0.3.190-movn8hpfe.exe?ex=6a9a8ddf&is=6a993c5f&hm=d72b04bfaae5a032ff238b3447b0922b3aed5aaf4a6272518ea764f8424e49a4&