APTMembers
APT

Void Arachne Hides DBatLoader Inside Fake FitGirl Game Repack Targeting Brazil

Two trojanised setup executables carrying DBatLoader are bundled inside a structurally convincing fake '007 First Light [FitGirl Repack]' installer, complete with inert decoy files designed to defeat sandbox analysis. The campaign, attributed to Void Arachne and targeting Brazilian users, routes C2 traffic through a pair of Cloudflare-proxied domains resolving to adjacent IPs in a personal Russian autonomous system.

Jun 9, 2026, 07:24 (UTC+9)Last seenJun 9, 2026Severity100ByCTX TeamActorVoid ArachneSilver FoxIOC23RegionsBR

Two unsigned PE32 executables — both carrying the version metadata "product: 007 First Light / copyright: FitGirl" — have been circulating through pirated-software distribution channels targeting Brazilian users, wrapped inside a structurally complete fake game repack that bundles a Play.bat launcher, a game cover image, a convincing uninstaller, and a counterfeit DirectX installer to defeat automated sandbox analysis.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence