Skip to content
View in the app

A better way to browse. Learn more.

Kaspersky Support Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

[Malware Reporting] Cryptominer disguised as libEGL.dll spreading via RPGMaker/TyranoScript games (Low Detection)

Hello,

I am writing to report a malicious sample currently circulating in pirated game distribution channels. It masquerades as the legitimate libEGL.dll file but contains a cryptocurrency miner.

Currently, it has a very low detection rate on VirusTotal (detected only by Huorong and Rising), and it bypasses most major AV engines.

Technical Details:

  • Malicious File: libEGL.dll

  • File Size: Approximately 525 KB (Note: Legitimate versions are typically around 377 KB).

  • SHA256: 8bacb2082eb37fd7aed5bb6a7fc766d9937d9f3ed926ae82420d37af754a216c

Behavioral Analysis:

  1. File Dropping:

    • Creates a directory at: C:\Users\%USERNAME%\AppData\Local\syscacheapp.

    • Drops a large executable named cacheapp64.exe (approx. 750 MB).

    • Characteristics of dropped file: Compiled with GCC/MinGW, extremely high entropy (packed/obfuscated), accompanied by numerous fake DLLs.

  2. Persistence:

    • Achieves auto-start by modifying the Registry:

    • Key: HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

Distribution & Context:

  • Vector: Confirmed presence in unauthorized/pirated releases of games (specifically those using RPGMaker or TyranoScript engines).

  • Sources: Widely distributed via major sharing communities such as anime-sharing, hentai-share, and ggbases.

  • Origin: The widespread nature suggests a potential "supply chain" poisoning within the upper-level crack/distribution groups.

Sample Download:

  • Link: [ https://files.catbox.moe/jmn65o.7z ]

  • Password: 123

  • Archive Structure: 1.7z contains libEGL.7z (The malware sample) and Attachment.7z (Screenshots and structural analysis).

Please analyze this sample and update the database.

Thank you.

 

https://metadefender.com/results/file/bzI1MTIyOHM0RHlFWkdCazQ4emVMdGdZM2w

https://www.virustotal.com/gui/file/021b7a9269bc251e66c4de170c7e81e7e9df482c386c84b7db6e86e986dcda10

https://www.virustotal.com/gui/file/8bacb2082eb37fd7aed5bb6a7fc766d9937d9f3ed926ae82420d37af754a216c

https://forum.kaspersky.com/topic/游戏libegldll存在挖矿病毒-57734/

 

 

 

Featured Replies

@inbox

Please continue here

Thank you.

  • The topic was locked
Guest
This topic is now closed to further replies.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.