VioletWorm - game.exe
A PyInstaller-packed Python loader that patches AMSI and ETW, checks for sandboxes, then drops an obfuscated .NET dropper which deploys a Venom/AsyncRAT-lineage remote access trojan. The RAT persists through startup, registry and scheduled tasks, and supports keylogging, screen and webcam capture, credential theft, file encryption and USB spreading.