Experts have found a trojan able to rig online live betting platforms

- JFrog found Newtonsoftt.Json.Net, a trojan NuGet package mimicking the popular Newtonsoft.Json library
- Malware specifically targeted Digitain’s crash‑game backend, rigging outcomes with insider knowledge of its codebase
- Issue was quickly fixed but attackers remain unidentified
Security researchers JFrog have discovered a unique trojan targeting one specific company, while letting everyone else who’s infected walk away unharmed.
Named Newtonsoftt.Json.Net, the trojan is a typosquatted NuGet package variant of the hugely popular JSON library called Newtonsoft.Json. The legitimate package is one of the most-used code libraries in the .NET programming world, needed by almost every project in existence. It is a small piece of software that helps .NET applications read, understand, and exchange data between different systems.
According to JFrog, someone published an almost identical package, copied the real author’s name, license, and made it work as intended. For almost anyone who installed it, it worked entirely normal. However, for developers working on Digitain’s crash-game backend, it’s a whole different story.
Rigging the games
Digitain is an Armenian software company providing online sports betting and gaming software platforms to gambling companies around the world.
On the infected machine running Digitain’s real crash-game code, the malware swaps in a rigged number instead of a fair one, using a formula based on the date and time.
What this means is that the results of the gambling game are rigged, allowing the attackers to know, in advance, which rounds are manipulated and place their bets accordingly.
The malware also sets up a private confirmation channel to report back for every rigged round, allowing the attackers to know if the cheat code still works or not.
JFrog did not identify the attackers, but they did stress that it was most likely an insider.
Apparently, only someone with inside knowledge of Digitain’s codebase (for example a current or former employee, or a contractor) could have built such an exploit, since it required knowledge of the exact internal function name inside Digitain’s game engine that decides the crash-game outcome.
The researchers reached out to Digitain on July 7 2026 and were notified, two days later, that the issue had already been escalated to the team and, in the meantime, fixed.
This is a preview from the original publisher. Continue reading at the source:
Read Full Article on techradar.com →
