Super Mario Virus: Infected Mario Forever Game in 2026

6 sources
Comments (0)

The Super Mario virus in 2026: the short answer

The so-called Super Mario virus is a fake installer for the free fan game Super Mario 3: Mario Forever. Cyble researchers found it in June 2023. The file, named Super-Mario-Bros.exe, installed the real game together with a Monero miner, the SupremeBot mining client and the Umbral information stealer.[4] The game itself is not malware. The danger is a modified copy downloaded from an unofficial site.

We found no new report in 2025 or 2026 of a fresh Mario Forever campaign. The files and addresses from 2023 are still useful if you want to check an old download. Searches such as "super mario v2 virus" did not lead us to any vendor report about a separate threat with that name, so treat any such file with the same care.

The trojanized Mario Forever installer at a glance
QuestionAnswer
What was foundA trojanized Super Mario 3: Mario Forever installer, Super-Mario-Bros.exe[4]
Files it droppedsuper-mario-forever-v702e.exe (the game), java.exe and atom.exe[4]
Malware insideA Monero (XMR) miner, the SupremeBot mining client and the Umbral stealer[4][5]
What Umbral stealsBrowser passwords and cookies, Discord tokens, Telegram sessions, Roblox cookies, Minecraft sessions, crypto wallet files, screenshots and webcam images[4]
Mining poolgulf[.]moneroocean[.]stream[4]
Status in 2026No new Mario Forever campaign found in the sources we read

Timeline of the Mario Forever malware

Timeline of the trojanized Super Mario 3 Mario Forever installer from the 2003 fan game release to the June 2023 Cyble report and the 2026 status
Timeline of the trojanized Mario Forever installer. Sources: Cyble, Malwarebytes, Kaspersky.
Dated events
DateEvent
2003Buziol Games releases Super Mario 3: Mario Forever, as our original report notes
June 23, 2023Cyble publishes its analysis of the trojanized installer[4]
June 2023Malwarebytes reports on the miners, SupremeBot and the Umbral stealer[5]
2023Kaspersky advises players to download games only from official sources[6]
2026We found no new campaign that reuses the Mario Forever installer

What changed since 2023

The 2023 campaign did not exploit a bug in the game. It simply bundled malware with a trusted name. When the installer runs, the game installs normally, so the player sees nothing wrong while the miner and SupremeBot start in the background.[4][6] Cyble found that SupremeBot copies itself into the game folder and creates a scheduled task that runs every 15 minutes.[4]

The Umbral stealer is the part that still matters for victims today. It adds itself to the Windows Defender exclusion list and tries to turn Defender off when tamper protection is not enabled.[4] It also takes the accounts that gamers care about most: Discord tokens, Roblox cookies, Minecraft session files and Telegram sessions.[4] A token taken in 2023 can still open an account today if the password and sessions were never reset.

Kaspersky's advice from the same period is still the basic rule. Download games only from official sources, avoid pirated copies from shady sites and torrents, and be careful with mods and cheats.[6]

Risks and scams around free game downloads (our analysis)

This list is our analysis of how fake game installers usually reach players. It builds on the 2023 reports but is not taken from one vendor.

  • Free remakes of famous games. Fan games like Mario Forever are not sold in large stores, so players look for them on download sites. That gap is easy to fill with a fake copy.
  • Search ads and poisoned search results. Our original report names malvertising and black hat SEO as the likely delivery routes.[1][2]
  • Cheats and mods. Kaspersky warns to be careful with mods and to avoid cheats entirely.[6]
  • Account takeover after the infection. Stolen Discord and Roblox sessions can be used to message friends with more malicious links.
  • A slow, hot PC. A miner uses your hardware to earn Monero for the attacker.[3][4] High fan noise and CPU use when idle are a typical sign.

What to do if you installed a Mario game from an unknown site

Six steps after installing a fake Super Mario game: check files, scan the PC, check Defender, remove tasks, reset passwords and tokens, download only from official sources
Six steps after installing a suspicious Mario game. 2-Spyware, 2026.

1. Check the files. Look in the game folder for java.exe and atom.exe. Cyble lists them as the miner and the SupremeBot dropper.[4] A Mario game has no reason to ship them.

2. Scan the PC. Run a full scan with an up-to-date security tool. Our virus removal guides explain how to remove miners and stealers.

3. Check Windows Defender. Turn on tamper protection and look at the Defender exclusion list. Umbral adds itself there and may switch Defender off.[4] Also check the hosts file, which the old report says the malware changes.

4. Remove unknown scheduled tasks. SupremeBot runs from a task every 15 minutes.[4] Delete tasks you did not create, after the scan confirms what they are.

5. Reset accounts from a clean device. Change passwords for email, banking, Discord, Roblox, Minecraft and Telegram, and sign out of all sessions so stolen tokens stop working. See if your email appears in a leak with our leak check.

6. Download games only from official sources. Use the publisher's site or a large store, as Kaspersky also advises.[6]

What is still unknown

  • How many players installed the trojanized Mario Forever installer. The reports we read give no victim count.[4][5]
  • Which site or ad first spread the file. The original report says only that malvertising and black hat SEO were the likely routes.
  • Whether files sold or shared as "Super Mario V2" or mario3.exe are linked to this campaign. We found no vendor report that says so.

Our original 2023 report

The text below is our report as first published in 2023. We keep it unchanged for the record; the sections above bring it up to date.

A trojanized installer for the popular Super Mario 3: Mario Forever game for Windows has been discovered, posing a serious risk to unwary players. This modified version of the game installer, which was distributed through unknown channels, contains a number of malware infections that can jeopardize the security and privacy of affected systems.

Super Mario 3: Mario Forever, released in 2003 by Buziol Games, is a free-to-play remake of the classic Nintendo game. It quickly gained popularity and was downloaded by millions of users who wanted to relive the nostalgic experience, thanks to updated graphics, modernized styling, and familiar gameplay mechanics.

Unfortunately, cybercriminals have exploited the game's popularity by distributing a trojanized version of it. The infected installer is most likely distributed through malicious advertising techniques such as malvertizing[1] and Black SEO.[2]

Malicious payloads hidden within the trojanized installer

Users unknowingly introduce multiple malicious payloads onto their systems when they run the trojanized installer. The installer extracts three executables: the legitimate Super Mario 3: Mario Forever game installer and two additional files called "java.exe" and "atom.exe."

The "java.exe" file functions as a Monero (XMR) cryptocurrency miner,[3] mining Monero coins using the victim's hardware resources. It connects to a mining server at "gulf[.]moneroocean[.]stream" and begins stealing money from the victim's system.

"atom.exe" on the other hand, installs SupremeBot, a stealthy mining client. To avoid detection, this malware creates a hidden duplicate of itself within the game's installation directory. It also creates a scheduled task that runs the duplicate every 15 minutes while masquerading as a legitimate process name.

Expanding threats and data theft

The trojanized Super Mario game installer does more than just mine cryptocurrency. It also employs Umbral Stealer, an open-source information stealer. This advanced malware can steal sensitive data from infected Windows devices.

Umbral Stealer targets a variety of valuable information, such as stored passwords, session tokens from web browsers, credentials for popular platforms such as Discord, Minecraft, Roblox, and Telegram, and cryptocurrency wallets. Furthermore, the malware can take screenshots of the victim's desktop and use connected webcams to capture media.

Umbral Stealer disables Windows Defender if tamper protection is not enabled and adds its process to the Defender's exclusion list to avoid detection. Furthermore, the malware modifies the Windows hosts file to prevent popular antivirus products from communicating with their respective company websites, rendering them less effective.

Protecting against Super Mario game malware and ensuring security

If you recently downloaded Super Mario 3: Mario Forever, you must immediately scan your computer for any installed malware and remove it. Password resets are strongly advised for sensitive sites such as banking, financial, cryptocurrency, and email platforms.

Remember to use unique and strong passwords for each site when resetting passwords, and use a password manager to securely store them. Furthermore, only download games and software from official sources, such as the publisher's website or reputable digital content distribution platforms.

To strengthen your defenses, scan downloaded executables with up-to-date antivirus software before running them. Updating your security tools on a regular basis ensures that you are protected against emerging threats and vulnerabilities. By remaining vigilant and adhering to these security practices, you can reduce your chances of becoming a victim of trojanized games and other malware attacks, protecting your digital life and personal information.

Frequently asked questions

Is there a Super Mario virus?

Yes, in the sense that criminals spread a trojanized installer for Super Mario 3: Mario Forever. Cyble found in June 2023 that it installed the real game plus a Monero miner, the SupremeBot mining client and the Umbral stealer.{4} The original game is not a virus; the risk comes from modified copies.

Is Mario Forever a virus?

No. Super Mario 3: Mario Forever is a free fan remake released in 2003 by Buziol Games. The problem is fake installers, such as the Super-Mario-Bros.exe file Cyble analyzed, which bundled malware with the game.{4} Download it only from a source you trust and scan the file first.

What is the Super Mario V2 virus?

We found no security vendor report about a separate threat called Super Mario V2. The confirmed case is the trojanized Mario Forever installer from 2023.{4}{5} Treat any Mario game file from an unknown site as risky and scan it before running it.

Is mario3.exe safe?

We cannot confirm it either way, because mario3.exe is not named in the reports we read. The 2023 fake installer used the names Super-Mario-Bros.exe, super-mario-forever-v702e.exe, java.exe and atom.exe.{4} Check where the file came from and scan it with an up-to-date security tool.

What does the Super Mario malware steal?

The Umbral stealer in the fake installer takes browser passwords and cookies, Discord tokens, Telegram sessions, Roblox cookies, Minecraft sessions and crypto wallet files. It can also capture screenshots and webcam images.{4} Change those passwords and sign out of all sessions if you ran the file.

How can malware infect your gaming device?

Most often through files you install yourself. Fake game installers, cheats and mods from unofficial sites can carry miners and stealers, as the Mario Forever case shows.{4}{6} Download games only from official stores and keep your security tools updated.

Comments (0)

What do you think?

0 comments

No comments yet. Be the first.

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year