
Pirated Mortal Kombat Installer Feeds Debugger-Aware Loader Chain
Two unsigned, identically-branded 'Mortal Kombat 1'/FitGirl crack installers act as entry points for a DBatLoader-to-DonutLoader chain that checks for attached debuggers before fetching a second-stage payload over plain HTTP. The lure trades precision for volume, relying on gamers to voluntarily run the dropper.
Two unsigned Win32 installers dressed up as a pirated "Mortal Kombat 1" setup from the FitGirl repack scene are functioning as the entry point for a debugger-aware loader chain that ends with a second-stage payload fetched over plain HTTP. Both files carry identical product and copyright metadata — "Mortal Kombat 1" and "FitGirl" — and both use the meaningful name setup.exe, with one retaining the full internal path E:\Mortal_Kombat_1_--_fitgirl-repacks.site\setup.exe. Neither is code-signed.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read