Exposing the Deception: Russian EFF Impersonators Behind Stealc & Pyramid C2
March 5, 2025, 4:39 p.m.
Description
A threat group impersonating the Electronic Frontier Foundation (EFF) is targeting Albion Online players through phishing messages and decoy documents. The campaign uses malware such as Stealc stealer and Pyramid C2 to compromise player accounts. Analysis of an exposed directory revealed PowerShell scripts, PDFs, and malicious payloads. The infrastructure includes multiple servers sharing SSH keys. Code comments suggest Russian-speaking developers. The attackers use EFF's reputation to lend credibility while executing malware in the background. The campaign exploits the game's player-driven economy, where in-game assets have real-world value. Mitigation strategies include cautious handling of unsolicited communications and verifying sources' authenticity.
Tags
Date
- Created: March 4, 2025, 10:43 p.m.
- Published: March 4, 2025, 10:43 p.m.
- Modified: March 5, 2025, 4:39 p.m.
Attack Patterns
- Pyramid C2
- Stealc
- T1059.006
- T1132.001
- T1573.001
- T1027.002
- T1204.001
- T1059.001
- T1566.002
- T1547.001
- T1071.001
- T1204.002
- T1573
- T1547
- T1566.001
- T1071
- T1204
- T1140
- T1132
- T1027
- T1566
- T1059