FILEMembers
FILE

Fake 'Elden Ring' Launcher Fools Sandboxes, Not 52 AV Engines

A dropper posing as an Elden Ring installer draws malicious verdicts from 52 of 75 antivirus engines yet slips past both sandboxes that analyzed it undetected. Tied to the espionage-focused Snowglobe/babar cluster, it relocates itself into the Windows system folder and pings an unlisted .cc domain, while a dormant-then-reactivated domain, koodgame.com, hints at coordinated infrastructure staging around a Thailand telecom targeting campaign.

Jul 6, 2026, 02:52 (UTC+9)Last seenJul 6, 2026Severity75ByCTX TeamActorSnowglobeAnimal FarmIOC4MITRE22RegionsTH

A binary calling itself "Elden Ring.exe" — and, in an alternate build, "Launcher Elden Ring.exe" — is not a cracked copy of a hit fantasy RPG. It is a dropper that static engines recognize almost immediately and dynamic sandboxes almost entirely miss, a split that is the real story here. Fifty-two of 75 antivirus engines flag the file (hash 32f34fb30fd47ab761e94306bc30432cd41d67309ab1e6b2599be2d70d3bd285) as malicious, carrying the label trojan.rancor/usblek26 along with community tags of…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence