APTMembers
APT

Sims 4 Crack Lure Delivers CyberGate RAT Across Nine Countries

A campaign attributed to the Snowglobe threat actor is distributing CyberGate/Rebhip remote access trojans disguised as pirated Sims 4 installers and updaters. The payloads combine NSIS dropper wrapping, active sandbox detection, and XOR-obfuscated PE stubs to defeat automated analysis pipelines before reaching victims in education and telecommunications sectors across Europe, Southeast Asia, and North America.

May 30, 2026, 20:24 (UTC+9)Last seenMay 30, 2026Severity82ByCTX TeamActorSnowglobeAnimal FarmIOC12MITRE41RegionsBELTPLRSSE

Three Windows executables dressed as Sims 4 crack installers and updaters are circulating across nine countries, carrying a CyberGate/Rebhip remote access trojan beneath a multi-layer evasion stack that combines NSIS dropper wrapping, active sandbox product-ID detection, and XOR-obfuscated PE stubs — a tradecraft combination deliberately engineered to defeat automated analysis pipelines before a human analyst ever sees the payload.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence