Digitain: Betting Trojan Disguises Stolen Round Results as Legitimate Seq Logging Traffic

Digitain: Betting Trojan Disguises Stolen Round Results as Legitimate Seq Logging Traffic

Malicious NuGet Package Targets Digitain’s Betting Backend with Rigged Game Results

Security researchers at JFrog uncovered a sophisticated supply-chain attack leveraging a typosquatted NuGet package, Newtonsoftt.Json.Net, designed to impersonate the legitimate Newtonsoft.Json library. The malicious package, disguised as a standard JSON framework, selectively targeted Digitain’s FG-Crash betting backend to manipulate game outcomes and exfiltrate results to an attacker-controlled server.

The package, versions 11.0.4 through 11.0.11, closely mimicked the official Json.NET branding, including metadata pointing to the real project URL and a plausible versioning scheme. Under the hood, it bundled a trojanized fork of Newtonsoft.Json, a payload DLL, and the Harmony runtime-patching library, ensuring malicious code executed whenever the JSON library was invoked.

The attack employed a delayed trigger via a booby-trapped JsonConvert.DefaultSettings setter, replacing the host’s resolver and scheduling a Harmony patch to activate minutes or hours later. Once active, the malware hooked GenerateGameResult, altering crash-game coefficients using deterministic lookup tables or direct return-value manipulation based on time-based variables (e.g., month, day of week, or a 22:00 UTC window). Exfiltrated data was disguised as Seq logging traffic, blending with legitimate observability data to evade detection.

The campaign was narrowly scoped, focusing solely on manipulating Digitain’s crash-game results for financial gain rather than credential theft or lateral movement. The attacker exploited a pre-known schedule of rigged rounds, enabling preferential payouts or guaranteed wins while limiting exposure by unhooking Harmony after a set number of manipulations.

JFrog responsibly disclosed the issue to Digitain, which confirmed the threat had been identified and mitigated. However, details on whether the attack resulted in production exploitation remain undisclosed. The malicious package has since been unlisted from NuGet.

Source: https://cyberpress.org/betting-trojan-round-spoofing/

Digitain TPRM report: https://www.rankiteo.com/company/digitain-

"id": "dig1784708631",
"linkid": "digitain-",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Online Betting/Gaming',
                        'name': 'Digitain',
                        'type': 'Company'}],
 'attack_vector': 'Typosquatted NuGet Package',
 'data_breach': {'data_exfiltration': 'Exfiltrated to attacker-controlled '
                                      'server via disguised *Seq* logging '
                                      'traffic',
                 'sensitivity_of_data': 'High (betting outcomes)',
                 'type_of_data_compromised': 'Game results and coefficients'},
 'description': 'Security researchers at JFrog uncovered a sophisticated '
                'supply-chain attack leveraging a typosquatted NuGet package, '
                '*Newtonsoftt.Json.Net*, designed to impersonate the '
                'legitimate *Newtonsoft.Json* library. The malicious package '
                'selectively targeted Digitain’s *FG-Crash* betting backend to '
                'manipulate game outcomes and exfiltrate results to an '
                'attacker-controlled server.',
 'impact': {'data_compromised': 'Game results and coefficients',
            'operational_impact': 'Manipulation of game outcomes',
            'systems_affected': 'Digitain’s *FG-Crash* betting backend'},
 'investigation_status': 'Mitigated',
 'motivation': 'Financial gain',
 'post_incident_analysis': {'corrective_actions': 'Unlisting of malicious '
                                                  'package, mitigation of '
                                                  'affected systems',
                            'root_causes': 'Typosquatted NuGet package with '
                                           'delayed malicious payload'},
 'references': [{'source': 'JFrog'}],
 'response': {'containment_measures': 'Malicious package unlisted from NuGet',
              'remediation_measures': 'Mitigation confirmed by Digitain',
              'third_party_assistance': 'JFrog'},
 'title': 'Malicious NuGet Package Targets Digitain’s Betting Backend with '
          'Rigged Game Results',
 'type': 'Supply-Chain Attack',
 'vulnerability_exploited': 'Supply-chain compromise via malicious dependency'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.