FILEMembers
FILE

Snowglobe Backdoor Hides in GTA V Launcher to Hit Thai Telecoms

A Babar-family implant attributed to the Snowglobe actor cluster is targeting Thailand's telecommunications sector behind a trojanised Grand Theft Auto V launcher. The payload deploys a five-layer evasion stack — including PE timestomping, dynamic API resolution, Extra Window Memory injection, NTFS alternate data stream hiding, and Cloudflare-proxied C2 — that defeats detection at every stage of the kill chain.

May 24, 2026, 17:57 (UTC+9)Last seenMay 24, 2026Severity73ByCTX TeamActorSnowglobeAnimal FarmIOC5MITRE21RegionsTH

A 32-bit Windows executable named "Grand Theft Auto V Enhanced.exe" — one of four GTA V-branded filename variants circulating in this campaign — is not what it claims to be. Behind the high-recognition game title sits a Babar-family backdoor attributed to the Snowglobe actor cluster (also tracked as Animal Farm and Sig20), directed at telecommunications operators in Thailand under an espionage mandate.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence