
Fake 'Elden Ring' Launcher Fools Sandboxes, Not 52 AV Engines
A dropper posing as an Elden Ring installer draws malicious verdicts from 52 of 75 antivirus engines yet slips past both sandboxes that analyzed it undetected. Tied to the espionage-focused Snowglobe/babar cluster, it relocates itself into the Windows system folder and pings an unlisted .cc domain, while a dormant-then-reactivated domain, koodgame.com, hints at coordinated infrastructure staging around a Thailand telecom targeting campaign.
A binary calling itself "Elden Ring.exe" — and, in an alternate build, "Launcher Elden Ring.exe" — is not a cracked copy of a hit fantasy RPG. It is a dropper that static engines recognize almost immediately and dynamic sandboxes almost entirely miss, a split that is the real story here. Fifty-two of 75 antivirus engines flag the file (hash 32f34fb30fd47ab761e94306bc30432cd41d67309ab1e6b2599be2d70d3bd285) as malicious, carrying the label trojan.rancor/usblek26 along with community tags of…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read