Game.exe is a custom remote access trojan/backdoor masquerading as a legitimate Microsoft WebView2 application. In the reported intrusion chain, attackers used a downloader named ms_upd.exe—installed via curl—to contact moonzonet[.]com and deploy additional payloads including Game.exe, WebView2Loader.dll, and an encrypted configuration file named visualwincomp.txt. Rapid7 reported that Game.exe was built from a trojanized WebView2APISample project and, in one analyzed sample, had SHA256 1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6. The malware used anti-analysis and anti-VM techniques including dynamic API resolution, string obfuscation, sandbox DLL checks, virtualization checks, removable drive enumeration, and sleep timing checks. It established persistence by copying itself into a randomized C:\ProgramData\visualwincomp-<random>\ directory. The encrypted configuration was decrypted with AES-256-GCM to recover C2 information; Game.exe then connected to uploadfiler[.]com over port 443, polled /index.php every 60 seconds, and sent command results to /profile. Reported capabilities include sending victim host information, cmd.exe and PowerShell command execution, file upload including chunked upload, file deletion, starting and stopping interactive CMD and PowerShell shells, writing base64-encoded files, and re-registration with C2. The malware was observed in an intrusion that Rapid7 attributed with moderate confidence to the Iranian state-linked group MuddyWater (also known as Seedworm), which used Microsoft Teams social engineering, credential theft, MFA manipulation, RDP, DWAgent, and in some cases AnyDesk to gain and maintain access. The broader operation was described as espionage-focused and disguised with Chaos ransomware branding as a false flag; affected organizations included U.S.-based targets, and the reporting notes MuddyWater has historically targeted government, critical infrastructure, financial, airport, defense, and aerospace organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A curl command was used to install a downloader called “ms_upd.exe,” which contacted the command-and-control (C2) domain “moonzonet[.]com” and installed additional payloads including a custom backdoor called “Game.exe.” Game.exe is a trojanized version of the legitimate Microsoft WebView2 application, and performs a range of anti-analysis checks before connecting to the C2 domain “uploadfiler[.]com.”
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware deviates from the dropper in a way that it implements some obfuscation and anti analysis techniques... String Obfuscation... Encrypted configuration
Dynamic API and DLL resolution Hide the malware functionality Usage of LoadLibraryA() and GetProcAddress() APIs
Next, they leveraged a malware loader (ms_upd.exe) to drop a custom backdoor (Game.exe), disguised as a Microsoft WebView2 application.
Game.exe is a trojanized version of the legitimate Microsoft WebView2 application, and performs a range of anti-analysis checks before connecting to the C2 domain “uploadfiler[.]com.”
Sandbox Detection Search for known analysis-related DLLs that are loaded into the current process sbiedll.dll, dbghelp.dll, api_log.dll, vmcheck.dll, wpespy.dll
Removable Drive Enumeration Enumerate logical drives and check if any removable drives are present Usage of GetLogicalDrives() and GetDriveTypesA() to enumerate logical drives and compare their type against DRIVE_REMOVABLE | The binary functions as a downloader that begins by collecting basic host information, including computer name, username, and domain.
MITRE ATT&CK techniques... T1087 Account Discovery Identifying user accounts via commands
Game.exe is a trojanized version of the legitimate Microsoft WebView2 application, and performs a range of anti-analysis checks before connecting to the C2 domain “uploadfiler[.]com.”
Sandbox Detection Search for known analysis-related DLLs that are loaded into the current process sbiedll.dll, dbghelp.dll, api_log.dll, vmcheck.dll, wpespy.dll
The RAT decrypts its configuration using AES-256-GCM to extract the attacker’s C2 server hostname uploadfiler[.]com and port 443... it enters an infinite loop polling /index.php every 60 seconds.
The malware sends victim host information to the C2 and then infinitely polls the server for incoming commands every 60 seconds.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Game.exe is a custom backdoor delivered by ms_upd.exe. It is a trojanized Microsoft WebView2 application that performs anti-analysis checks, sends host information to C2, polls for commands, and supports command execution, file write/delete actions, and interactive shell control.
Custom remote access trojan/backdoor that masquerades as a Microsoft WebView2 sample application. It decrypts configuration data, registers with C2, persists under ProgramData, polls for commands, and supports arbitrary command execution, PowerShell execution, file upload, file deletion, and interactive shells while using anti-analysis and anti-VM techniques.
A custom backdoor dropped by ms_upd.exe and disguised as a Microsoft WebView2 application. It includes anti-analysis and anti-VM checks and supports command execution, file operations, and persistent shell access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.