APTMembers
APT

Pirated Mortal Kombat Installer Feeds Debugger-Aware Loader Chain

Two unsigned, identically-branded 'Mortal Kombat 1'/FitGirl crack installers act as entry points for a DBatLoader-to-DonutLoader chain that checks for attached debuggers before fetching a second-stage payload over plain HTTP. The lure trades precision for volume, relying on gamers to voluntarily run the dropper.

Sep 9, 2026, 22:29 (UTC+9)Last seenSep 9, 2026Severity100ByCTX TeamActorVoid ArachneSilver FoxIOC17RegionsBR

Two unsigned Win32 installers dressed up as a pirated "Mortal Kombat 1" setup from the FitGirl repack scene are functioning as the entry point for a debugger-aware loader chain that ends with a second-stage payload fetched over plain HTTP. Both files carry identical product and copyright metadata — "Mortal Kombat 1" and "FitGirl" — and both use the meaningful name setup.exe, with one retaining the full internal path E:\Mortal_Kombat_1_--_fitgirl-repacks.site\setup.exe. Neither is code-signed.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence