typetechniqueconfidencehighcreated2026-08-17updated2026-08-20masqueradesigned-binary-abusesteamvalve

steam-error-reporter-masquerade

Abuse of Valve's legitimate Steam Error Reporter (steamerrorreporter64.exe) — a signed MSVC C++ x64 binary — by repackaging it inside a 7-Zip SFX archive alongside encrypted companion files. The binary's authentic PDB path (c:\buildslave\steam_rel_client_hotfix_win64\...), Valve certificate, and runtime DLL imports (tier0_s64.dll, vstdlib_s64.dll) make it appear benign during superficial triage, while the actual malicious logic resides in an encrypted companion file decrypted at runtime.

Static Fingerprint

  • PE32+ x64, MSVC compiled (typically Mar 2024)
  • PDB path: steamerrorreporter\win64\Release\steamerrorreporter64.pdb
  • Authenticode signed (CN = Valve Corporation)
  • Imports: KERNEL32.dll (110), tier0_s64.dll (13), vstdlib_s64.dll (13), PSAPI.DLL (2), WININET.dll (11)
  • No exports
  • Resources: RT_ICON (9), RT_VERSION, RT_MANIFEST

Companion Files

The SFX archive typically bundles:

  • tier0_s64.dll, vstdlib_s64.dll — legitimate Valve runtime (for camouflage)
  • msvcp_win.dll, ucrtbase.dll — Microsoft CRT
  • network-mon.map — large (6–7 MB), entropy ~0.99/8, encrypted payload
  • process.xml — smaller companion config, same encoding

Observed Samples

  • 642ecaab (INUS.exe) — 7-Zip SFX wrapper, inner Vect_P16.exe ^[raw/analyses/642ecaab/report.md]
  • 9410374b — Confirmed twin of 642ecaab: same inner payload (SHA-256 0a0c0975...), same sidecar files (network-mon.map, process.xml), same Steam Error Reporter masquerade. Only the outer SFX wrapper differs. ^[/intel/analyses/9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3.html]

Related