typeentityfamilyd52f85confidencemediumcreated2026-06-09updated2026-08-03malware-familypemsvcthemidaloaderanti-debugdefense-evasionmasqueradingsigningevasion

d52f85

OpenCTI internal family label for payloads dropped by the Amadey downloader botnet. In this corpus, d52f85 has been observed on a Counter-Strike 2 external cheat overlay (sample 2fb095b1), distinct from the 9d2ca3 Amadey cluster. The label is best treated as a distribution-channel grouping rather than an intrinsic malware family.

Overview

OpenCTI assigns d52f85 to samples co-tagged dropped-by-amadey. The PacketPursuit corpus has now observed two distinct build morphs under this label:

  1. CS2 "Cheetah" external cheat (2fb095b1) — 4.6 MB MSVC 14.50 PE32+ overlay cheat with ImGui, NtRead/WriteVirtualMemory, no packing. ^[/intel/analyses/2fb095b1ad49aa816bc15a373bc7ffdf70eddc37a66e0f647c834d4413290150.html]
  2. Themida-packed Ubisoft Connect masquerade (78434b53) — 3.3 MB PE32+ x64 with Themida/WinLicense .boot decompressor, forged Ubisoft Connect version-info, six PNG icons, and a fabricated self-signed CN=Lightshot certificate with DigiCert timestamp counter-signature. The actual malicious payload is fully encrypted inside the .boot stub. ^[/intel/analyses/78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd.html]

Unlike the 9d2ca3 cluster — which contains MinGW droppers, Go infostealers, and .NET hollowing payloads — these samples share only the Amadey delivery channel. The label is best treated as a distribution-channel grouping rather than an intrinsic malware family.

Build Stack

Two confirmed morphs under this distribution label:

Morph A: CS2 "Cheetah" external cheat (2fb095b1)

  • Toolchain: MSVC 14.50 (Visual Studio 2022 v143), C++20, UCRT/ConCRT runtime.
  • Format: PE32+ x86-64, 6 sections (.text, .rdata, .data, .pdata, .rsrc, .reloc).
  • Linker flags: ASLR + DEP + High Entropy VA; Terminal Server Aware.
  • Signing: Unsigned.
  • PDB: C:\Users\nikor\source\repos\cheetah\x64\Release\cheetah.pdb — developer identity leak.
  • Obfuscation / packing: None. No UPX, Themida, VMProtect, or custom packer. Section entropies (6.29–6.67) are consistent with compiled C++ + ImGui + embedded font bitmaps.
  • Anti-analysis: None observed. No anti-VM, anti-debug, or sandbox gating.

Morph B: Themida-packed Ubisoft Connect masquerade (78434b53)

  • Toolchain: MSVC 14.29 (Visual Studio 2019 v142), C/C++.
  • Format: PE32+ x86-64, 8 sections (5 blank-name, .rsrc, .idata, .themida, .boot).
  • Linker flags: ASLR + DEP + High Entropy VA; Terminal Server Aware.
  • Signing: Fabricated self-signed CN=Lightshot with DigiCert timestamp counter-signature (post-dated 2026).
  • Packing: Themida/WinLicense — .themida placeholder (virtual-only), .boot LZ77 decompressor stub, blank section names, 3 imports (GetModuleHandleA, GetActiveWindow, BitBlt).
  • Masquerade: Complete Ubisoft Connect version-info (v4.1.9718.720), XML assembly manifest, 6 PNG icons (256×256 to 16×16).
  • Anti-analysis: Heavy Themida obfuscation eliminates static API surface; actual payload encrypted/compressed inside .boot.

Deploy / TTPs

Technique ID Evidence
Process Injection (cross-process memory manipulation) T1055.012 NtReadVirtualMemory, NtWriteVirtualMemory against cs2.exe / client.dll ^[/intel/analyses/2fb095b1ad49aa816bc15a373bc7ffdf70eddc37a66e0f647c834d4413290150.html]
Input Capture (API hooking / synthesis) T1056.004 NtUserInjectMouseInput, NtUserInjectKeyboardInput via win32u.dll for aimbot input injection
Discovery: Process Discovery T1057 CreateToolhelp32Snapshot, K32EnumProcessModulesEx, Process32FirstW/NextW to enumerate target game modules
Collection: Screen Capture T1113 ImGui overlay + screenshot capability used for ESP/radar
Defense Evasion: Masquerading T1036 "Essentials External v1.3" branding; game-cheat masquerade

Capabilities

  • themida-packed-lz77-decompressor
  • version-info-masquerade
  • certificate-fabrication-self-signed
  • timestamp-counter-signature-masquerade
  • embedded-icon-suite-masquerade
  • external-process-memory-read
  • external-process-memory-write
  • input-injection-mouse-keyboard
  • game-state-schema-loader-json
  • imgui-overlay-render
  • aimbot-prediction-smoothing
  • esp-team-visibility-filter
  • chams-wireframe-rimlight
  • radar-overlay-mini-map
  • recoil-control-system
  • velocity-bunny-hop-assist
  • create-toolhelp-process-discovery
  • no-c2-self-contained
  • admin-elevation-gate

Notable Analyses

  • /intel/analyses/2fb095b1ad49aa816bc15a373bc7ffdf70eddc37a66e0f647c834d4413290150.html — Deep static analysis of the CS2 "Cheetah" external cheat.
  • /intel/analyses/78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd.html — Themida-packed Ubisoft Connect masquerade with fabricated Lightshot certificate.

Related

  • 9d2ca3 — Amadey-downloader-dropped second-stage payload cluster (MinGW + Go + .NET variants). Shares the dropped-by-amadey co-label but is build-distinct from this sample.
  • Amadey downloader (external, Malpedia win.amadey) — the upstream delivery mechanism.