APTMembers
APT

Snowglobe Adds Chrome-Extension Droppers, Leaves cheater.to Untouched

Six new file indicators join CTX Team's record on the Cloudflare-fronted domain cheater.to, led by two unsigned files typed as Chrome Extension containers whose internal paths resolve to Windows .exe files. The infrastructure — domain, certificate, registrar — remains exactly as previously catalogued.

Jun 20, 2026, 15:58 (UTC+9)Last seenJul 4, 2026Severity50ByCTX TeamActorSnowglobeAnimal FarmIOC10MITRE43RegionsCZLTSATRUA

Six new file indicators have joined the record CTX Team has been building around a Cloudflare-fronted domain called cheater.to — and none of them are new domains or IPs. That distribution alone is the story. The most consequential pair in the batch are two files that VirusTotal types as "Google Chrome Extension" containers, complete with the magic string "Google Chrome extension, version 3, XZ compressed, CRC64" — yet whose internal file paths resolve to ordinary Windows executables:…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence