Gamers searching for cheat codes are being lured into downloading a Lua-based malware that establishes persistence on infected systems and delivers additional payloads. Disguised within Lua gaming engine supplements, the malware strain is prevalent globally. The malware is delivered via obfuscated Lua scripts which don’t raise suspicion as easily as compiled Lua bytecode. When downloaded, the malware establishes communication with a command-and-control server, maintaining persistence or downloading more payloads. The malware can replace cryptocurrency wallets and take screenshots.

QuirkyLoader: A New Malware Loader Spreading Infostealers and Remote Access Trojans (RATs) – GBHackers News
QuirkyLoader: A New Malware Loader Spreading Infostealers and Remote Access Trojans (RATs) GBHackers News