The hackers created a fake play-to-earn community “Cthulhu World,” including websites, Discord groups, social media accounts, and a Medium developer site, to distribute the Raccoon Stealer, AsyncRAT, and RedLine malware to unsuspecting victims.

See also: Microsoft: Iranian Mercury Group uses Log4Shell and targets organizations in Israel
As play-to-earn games become more popular, scammers and threat actors are increasingly targeting these new platforms for malicious activities.
Such is the case with a new malware distribution campaign discovered by cybersecurity researcher iamdeadlyz, where threat actors created an entire project to promote a fake play-to-earn game called Cthulhu World.
To promote the “project,” the threat actors are sending direct messages to users on Twitter asking if they would like to try out their new game. In exchange for testing and promoting the game, iamdeadlyz says the threat actors are promising a reward in Ethereum.

When visiting the now-defunct cthulhu-world.com website, users see a well-designed website containing information about the project and an interactive map of the environments .

However, this website appears to be a clone of the legitimate Alchemic World project, which warns users to stay away from the fake project.
The Cthulhu World website also has one big difference. When a user clicks on the arrow in the top right corner of the website, the visitor will be taken to a web page asking for a code to download the project's "alpha" test.
See also: Wiretapping Greece: Researchers reveal mass surveillance of telecommunications providers!
Threat actors share these passwords with potential victims as part of their Twitter DM conversations. A list of the passwords is also found in the website's source code, as shown below.

Depending on the password you entered, one of three files will be downloaded from DropBox.

Each of the three files installs a different malware, likely allowing threat actors to choose how they want to target a specific user. The three malware detected by AnyRun installs are AsyncRAT, RedLine Stealer , and Raccoon Stealer.
The Cthulhu World website is currently down, but their Discord remains active. It's unclear who on this Discord knows that the website is distributing malware, but some users clearly believe that this is a legitimate project.
See also: LockBit ransomware: Triple extortion tactic – DDoS attacks are also coming
As RedLine Stealer and Raccoon Stealer are known to steal cryptocurrency wallets, it is not surprising that some victims have already “cleaned” their wallets from this scam.

If you have visited Cthulhu-world.com and downloaded any of its software, you should immediately run an antivirus scan on your computer and remove anything detected.
Additionally, as these malware infections steal saved passwords, cookies , and crypto wallets, you will have to reset all passwords and create new wallets to import your cryptocurrency.
Ultimately, however, the wisest course of action is to reinstall your computer from scratch, as these malware infections provide full access to an infected computer and other undetected malware may still be installed.
Information source: bleepingcomputer.com
