Trojan.Scavenger is malware reported by Doctor Web in July 2025 that is designed to steal cryptocurrency and passwords. According to the provided content, it was distributed as game mods, patches, and cheats. Its execution was launched using legitimate software and also via exploitation of DLL Search Order Hijacking class vulnerabilities. No specific threat actor, targeted industry, victim geography, or concrete indicators of compromise are provided in the content beyond those delivery and capability details.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential/crypto stealer distributed as game mods/cheats/patches; execution involved legitimate software and abuse of DLL Search Order Hijacking class vulnerabilities.
Credential/crypto stealer distributed as game mods/cheats/patches; execution facilitated via legitimate software and DLL Search Order Hijacking-class weaknesses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.