Powercat malware campaign: Fake game cheats deliver infostealer
The Powercat malware campaign observed in February 2026 distributes an infostealer disguised as cheat software for popular PC games like Roblox, Minecraft, and Grand Theft Auto V. It uses a multi-stage infection chain involving an initial executable for profiling and persistence, followed by a Java-based loader that deploys the infostealer. The malware targets cryptocurrency wallets, browser data, Discord tokens, and gaming accounts with payment information. It also includes surveillance features such as keylogging, webcam capture, and screen recording. The campaign primarily targets children on gaming platforms and pay-to-cheat websites, with indications that stolen personal data may be used for blackmail or coercion into illegal activities.
AI Analysis
Technical Summary
Powercat is an active malware campaign delivering an infostealer payload disguised as utility or cheat software for popular PC games. The infection chain starts with an executable that profiles victims and establishes persistence, followed by a Java-based loader that installs the final infostealer. The malware targets sensitive data including cryptocurrency wallets (Exodus, Atomic, Monero-Gui), browser data from Chromium-based browsers, Discord tokens, and gaming accounts containing payment information. It also implements surveillance capabilities such as keylogging, webcam capture, and screen recording. The campaign specifically targets children frequenting gaming platforms and pay-to-cheat websites, with evidence suggesting the collected data may be exploited for blackmail or coercion into illegal activities.
Potential Impact
The malware compromises sensitive user data including cryptocurrency wallets, browser credentials, Discord tokens, and gaming accounts with payment information. It also enables continuous surveillance through keylogging, webcam capture, and screen recording, potentially leading to privacy violations and financial theft. The targeting of children increases the risk of exploitation and coercion using stolen personal information.
Mitigation Recommendations
No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Mitigation focuses on user education to avoid downloading cheat or utility software from untrusted sources, especially on gaming platforms. Employing updated antivirus and endpoint protection solutions capable of detecting multi-stage malware infections is recommended. Monitoring for suspicious processes and network activity related to Java-based loaders and infostealers can aid detection. Users should also secure cryptocurrency wallets and gaming accounts with strong, unique credentials and enable multi-factor authentication where possible.
Indicators of Compromise
- domain: powercat.dog
- hash: a33a96cbd92eef15116c0c1dcaa8feb6eee28a818046ac9576054183e920eeb5
- hash: 1d8e87144890cfe06a208c99a50748f7
- hash: ccb902ac93fce95a87d19262ef90688c
- hash: 725567384190916da37957e90bd5892a6b4fbe09
- hash: ac5bb68591b4350858878d2184bdac63cedfcb60
- hash: a9b4823a1b2c0702a1eb8a1bf18db2d9c9604d2d2dd98a99f1d388bf7cfa71e3
- hash: c0c3a0331b57d10d23a172a79bdf13ab066255de41774e5a19dd8a8e8446e1fa
- url: https://ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
- url: https://powercat.dog/cool
- url: https://powercat.dog/watermelon5
- domain: ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
- domain: alpha.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
- domain: beta.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
- domain: charlie.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
- domain: hotel.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
- domain: juliett.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
- domain: kilo.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
- domain: lima.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
- domain: oscar.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
Powercat malware campaign: Fake game cheats deliver infostealer
Description
The Powercat malware campaign observed in February 2026 distributes an infostealer disguised as cheat software for popular PC games like Roblox, Minecraft, and Grand Theft Auto V. It uses a multi-stage infection chain involving an initial executable for profiling and persistence, followed by a Java-based loader that deploys the infostealer. The malware targets cryptocurrency wallets, browser data, Discord tokens, and gaming accounts with payment information. It also includes surveillance features such as keylogging, webcam capture, and screen recording. The campaign primarily targets children on gaming platforms and pay-to-cheat websites, with indications that stolen personal data may be used for blackmail or coercion into illegal activities.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Powercat is an active malware campaign delivering an infostealer payload disguised as utility or cheat software for popular PC games. The infection chain starts with an executable that profiles victims and establishes persistence, followed by a Java-based loader that installs the final infostealer. The malware targets sensitive data including cryptocurrency wallets (Exodus, Atomic, Monero-Gui), browser data from Chromium-based browsers, Discord tokens, and gaming accounts containing payment information. It also implements surveillance capabilities such as keylogging, webcam capture, and screen recording. The campaign specifically targets children frequenting gaming platforms and pay-to-cheat websites, with evidence suggesting the collected data may be exploited for blackmail or coercion into illegal activities.
Potential Impact
The malware compromises sensitive user data including cryptocurrency wallets, browser credentials, Discord tokens, and gaming accounts with payment information. It also enables continuous surveillance through keylogging, webcam capture, and screen recording, potentially leading to privacy violations and financial theft. The targeting of children increases the risk of exploitation and coercion using stolen personal information.
Defensive Guidance
No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Mitigation focuses on user education to avoid downloading cheat or utility software from untrusted sources, especially on gaming platforms. Employing updated antivirus and endpoint protection solutions capable of detecting multi-stage malware infections is recommended. Monitoring for suspicious processes and network activity related to Java-based loaders and infostealers can aid detection. Users should also secure cryptocurrency wallets and gaming accounts with strong, unique credentials and enable multi-factor authentication where possible.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.threatlocker.com/blog/powercat-malware-campaign-fake-game-cheats-deliver-infostealer-targeting-discord-roblox-and-crypto-wallets"]
- Adversary
- null
- Pulse Id
- 6a79d611fbc9cb6fa6102a8b
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainpowercat.dog | — | |
domaince953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — | |
domainalpha.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — | |
domainbeta.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — | |
domaincharlie.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — | |
domainhotel.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — | |
domainjuliett.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — | |
domainkilo.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — | |
domainlima.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — | |
domainoscar.ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — |
Hash
| Value | Description | Copy |
|---|---|---|
hasha33a96cbd92eef15116c0c1dcaa8feb6eee28a818046ac9576054183e920eeb5 | — | |
hash1d8e87144890cfe06a208c99a50748f7 | — | |
hashccb902ac93fce95a87d19262ef90688c | — | |
hash725567384190916da37957e90bd5892a6b4fbe09 | — | |
hashac5bb68591b4350858878d2184bdac63cedfcb60 | — | |
hasha9b4823a1b2c0702a1eb8a1bf18db2d9c9604d2d2dd98a99f1d388bf7cfa71e3 | — | |
hashc0c3a0331b57d10d23a172a79bdf13ab066255de41774e5a19dd8a8e8446e1fa | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — | |
urlhttps://powercat.dog/cool | — | |
urlhttps://powercat.dog/watermelon5 | — |
Threat ID: 6a79f49ebf8831d53900df18
Added to database: 08/10/2026, 15:56:14 UTC
Last enriched: 08/10/2026, 16:33:32 UTC
Last updated: 08/10/2026, 16:33:32 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.