A fake-cheat campaign targeting players of Meccha Chameleon used GitHub repositories with fabricated popularity indicators to distribute an NSIS installer containing an Electron/JavaScript dropper, a Go loader, and the Remus infostealer. The dropper requests elevation, profiles the host, captures a desktop screenshot, reports infections through Telegram, adds Microsoft Defender exclusions, and repeatedly launches its loader through six execution mechanisms.
The Go loader decrypts and manually maps the Remus payload, which performs anti-analysis checks and steals browser, Roblox, Steam, clipboard, and other victim data. Remus can also receive operator-directed tasks to collect files, registry entries, browser extensions, and screenshots, or to execute arbitrary commands and payloads. The campaign's Telegram collection channel reportedly received data from more than 280 compromised hosts within roughly one day of its June 30 launch.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
During approximately one day after the campaign began, the attacker-operated Telegram collection channel received infection data from more than 280 hosts.
A campaign using GitHub repositories advertising fake Meccha Chameleon cheats began distributing an NSIS installer that ultimately deployed the Remus infostealer.
The analyzed Remus infostealer build recorded a build date of June 28, 2026 in its Info.yml victim profile.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.