
Snowglobe Backdoor Hides in GTA V Launcher to Hit Thai Telecoms
A Babar-family implant attributed to the Snowglobe actor cluster is targeting Thailand's telecommunications sector behind a trojanised Grand Theft Auto V launcher. The payload deploys a five-layer evasion stack — including PE timestomping, dynamic API resolution, Extra Window Memory injection, NTFS alternate data stream hiding, and Cloudflare-proxied C2 — that defeats detection at every stage of the kill chain.
A 32-bit Windows executable named "Grand Theft Auto V Enhanced.exe" — one of four GTA V-branded filename variants circulating in this campaign — is not what it claims to be. Behind the high-recognition game title sits a Babar-family backdoor attributed to the Snowglobe actor cluster (also tracked as Animal Farm and Sig20), directed at telecommunications operators in Thailand under an espionage mandate.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read