FILEMembers
FILE

Fake RDR2 Crack Installer Feeds DBatLoader Chain to Recycled Hosting

Two bogus 'FitGirl repack' setup.exe files claiming to be Red Dead Redemption 2 trigger a DBatLoader verdict and quietly chain into an MSIL downloader flagged as loader, stealer, and coinminer. One installer alone has been submitted nearly 15,000 times, and the delivery network runs on recycled certificates rather than fresh infrastructure.

Jul 15, 2026, 05:36 (UTC+9)Last seenJul 15, 2026Severity98ByCTX TeamActorVoid ArachneSilver FoxIOC16RegionsBRPT

Two "setup.exe" installers claiming to be a FitGirl-style repack of Red Dead Redemption 2 have quietly become one of the more efficient initial-access vectors observed on public malware-sharing telemetry this year — not because the lure is novel, but because of what happens after a victim runs it. Both installers trigger a DBatLoader sandbox verdict [T1204], and one of them has been submitted 14,889 times from 3,664 unique sources, a distribution footprint that reads less like a targeted…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence