A Trojanized installer for Super Mario 3: Mario Forever for Windows devices is infecting unsuspecting gamers with malware.

Super Mario 3: Mario Forever is a free remake of the classic Nintendo created by Buziol Games. It was released in 2003 for Windows. The game quickly became popular, with millions of users downloading it on their devices. What made it stand out was that it contained all the mechanics of the classic Super Mario series but with updated graphics and a more modern style and sound.
Development of the game continued for another decade. During this time, many new versions were released that brought bug and improvements. Today, it is considered a post-modern classic.
See also: NSA: To kill BlackLotus malware, patch is a good start
Super Mario 3: Mario Forever: Trojanized installer infects Windows devices
Cyble researchers have discovered that malicious actors are distributing a forged version of the Super Mario 3: Mario Forever installer . The file is distributed as a self-extracting archive executable through unknown channels.
The trojanized game is likely promoted on gaming forums, social media, while promotion through malvertizing, Black SEO , etc.
The file contains three executables. One of them is “super-mario-forever-v702e.exe”, which installs the legitimate game Mario. The other two executables are “java.exe” and “atom.exe”, which are “discreetly” installed in the victim’s AppData when the game is installed.
Once the malicious executables are on the disk, the installer program executes them to run an XMR (Monero) miner and a SupremeBot mining client.
The file “java.exe” is the Monero miner. The malware collects information about the victim’s hardware and connects to a mining server at “gulf[.]moneroocean[.]stream” to begin mining.
On the other hand, SupremeBot (“atom.exe”) creates a copy of itself and places this copy in a hidden folder in the game’s installation directory. After that, it creates a scheduled task to execute the copy, which runs every 15 minutes and hides itself under the name of a legitimate process.
See also: Powerful JavaScript Dropper PindOS Distributes Bumblebee and IcedID Malware
The original process is terminated and the original file is deleted to make it difficult to detect. The malware then establishes a C2 connection to transmit information and download the mining configuration to begin the Monero.
Finally, SupremeBot retrieves an additional payload from the C2, which arrives as an executable named “wime.exe”.
This final file is Umbral Stealer. It is an program -stealing information , available on GitHub since April 2023. The malware steals data from the infected Windows device.

The data it steals is information stored in web browsers, such as passwords and cookies containing session tokens, cryptocurrency wallets and credentials, and authentication tokens for Discord, Minecraft, Roblox, and Telegram.
Additionally, the malware can take screenshots of the victims' screens or use connected webcams to capture media. All stolen data is stored locally before being sent to the C2 server.
The malware that infects Super Mario 3 users can evade Windows Defender.
Additionally, the malware modifies the Windows hosts file to disrupt the communication of popular antivirus products with company websites, preventing their regular operation and effectiveness.
See also: Chinese hackers accidentally infected a European hospital with malware
Protection
If you have downloaded Super Mario 3: Mario Forever, you should check your computer for malware. If malware is detected, you should take steps to remove it from your device. Additionally, since Umbral Stealer steals information, you should reset your passwords to important services and sites. Remember to use a strong and unique password for different services.
Additionally, to reduce the chances of downloading malware hidden in seemingly legitimate games, choose only official sources such as the game publisher's website or trusted digital content distribution platforms.
Finally, always scan downloaded executable files using antivirus software and regularly update both devices and antivirus software.
Cybercriminals often use game installers to infect users with various malware. They do this because they know that games have a large user base and that hardcore gamers can easily fall for the trap.
Source: www.bleepingcomputer.com
