NEWS The Ureras virus has very narrow interests. He loves only poker and other people's screenshots

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,830
Why hack a bank if you can just look at someone else’s?
1777359738083.png
Malicious programs usually try to steal passwords or money. But Ureras has chosen a much narrower niche – he has been watching card games for years. And not for any, but for popular South Korean customers of poker and baduga. Back in 2012, Microsoft described the Urelas.C variant as a Trojan who tracked the processes of card games, took screenshots and sent them to a remote server along with system data. Then the list of goals included clients like baduki.exe, poker7.exe and others.

After 14 years, the scheme has not changed much. The Ureras sample, discovered in April 2026, still searches for running card games, take snapshots and sends them to control servers. The program monitors customers of poker, baduga and "high-low", cuts out the desired part of the window and packs images in JPEG format before sending.

It’s not about a single find. From mid-March to the end of April, more than 3 thousand samples of Urelas with unique hashes were recorded. In April alone, more than 2.3 thousand such files were accumulated. The activity is centered around the infrastructure of South Korean Internet providers, including SK Broadband and DLIVE.

Urelas does not try to become a universal tool that steals data. The logic is simpler and already: find the game window, take a picture, send. For card games, this is enough. All information about the party is directly on the screen - cards, bets, the state of the table and sometimes the account data.

The malware is launched in several stages. First creates an intermediate file, then the main executable module, as well as the hidden file of the configuration of golfinfo.ini. Inside, an encrypted state is stored with management server addresses and service parameters. After decryption, the program connects to several nodes, including 121.88.5.183 and 218.54.30.235.

An interesting detail is that one of the addresses (121.88.5.184) is not in the configuration and sewn directly in the code. This approach complicates the analysis and does not allow you to find the entire infrastructure.

The main load is screenshots. The program uses standard Windows features to capture the image, then trim the desired area and compresses the picture. The data obtained are sent in the form of special records of the protocol, where the images take central place.

Additionally, Ureras loads the HGDraw.dll auxiliary library. Inside is the code that captures the screen and which can be controlled by commands from the server. In fact, this is a separate module that conducts surveillance. As a result, we have a rare example of a malware that does not seek to cover everything. Urelas solves one problem, but solves it for years without changes: he monitors card desks and transmits what is happening to the server. Judging by the latest data, the scheme still works.
 

MATRİXELİTES

Well-known member
Member
Joined
Aug 4, 2026
Messages
443
Reaction score
138
Why hack a bank if you can just look at someone else’s?
View attachment 122
Malicious programs usually try to steal passwords or money. But Ureras has chosen a much narrower niche – he has been watching card games for years. And not for any, but for popular South Korean customers of poker and baduga. Back in 2012, Microsoft described the Urelas.C variant as a Trojan who tracked the processes of card games, took screenshots and sent them to a remote server along with system data. Then the list of goals included clients like baduki.exe, poker7.exe and others.

After 14 years, the scheme has not changed much. The Ureras sample, discovered in April 2026, still searches for running card games, take snapshots and sends them to control servers. The program monitors customers of poker, baduga and "high-low", cuts out the desired part of the window and packs images in JPEG format before sending.

It’s not about a single find. From mid-March to the end of April, more than 3 thousand samples of Urelas with unique hashes were recorded. In April alone, more than 2.3 thousand such files were accumulated. The activity is centered around the infrastructure of South Korean Internet providers, including SK Broadband and DLIVE.

Urelas does not try to become a universal tool that steals data. The logic is simpler and already: find the game window, take a picture, send. For card games, this is enough. All information about the party is directly on the screen - cards, bets, the state of the table and sometimes the account data.

The malware is launched in several stages. First creates an intermediate file, then the main executable module, as well as the hidden file of the configuration of golfinfo.ini. Inside, an encrypted state is stored with management server addresses and service parameters. After decryption, the program connects to several nodes, including 121.88.5.183 and 218.54.30.235.

An interesting detail is that one of the addresses (121.88.5.184) is not in the configuration and sewn directly in the code. This approach complicates the analysis and does not allow you to find the entire infrastructure.

The main load is screenshots. The program uses standard Windows features to capture the image, then trim the desired area and compresses the picture. The data obtained are sent in the form of special records of the protocol, where the images take central place.

Additionally, Ureras loads the HGDraw.dll auxiliary library. Inside is the code that captures the screen and which can be controlled by commands from the server. In fact, this is a separate module that conducts surveillance. As a result, we have a rare example of a malware that does not seek to cover everything. Urelas solves one problem, but solves it for years without changes: he monitors card desks and transmits what is happening to the server. Judging by the latest data, the scheme still works.
 
6,889Threads
91,817Messages
6,228Members
tweakuserLatest member
Top Bottom