216.73.216.6

A New Breed of Infostealer

· Published 13/05/2025 13:12 · Modified 21/05/2025 19:33

Export JSON

Essential information

Published
13/05/2025 13:12
Modified
21/05/2025 19:33
Tags
.net 2025-05-13 browser data chihuahua stealer crypto wallets encryption exfiltration infostealer multi-stage persistence powershell
Related entities
8 observables, 4 techniques (mitre), 1 malware

Description

A newly discovered .NET-based , , combines common malware techniques with advanced features. The infection begins with an obfuscated script shared via Google Drive, initiating a payload chain. is achieved through scheduled tasks, and the main payload targets and crypto wallet extensions. Stolen data is compressed, encrypted using AES-GCM via Windows CNG APIs, and exfiltrated over HTTPS. The malware employs stealth techniques, including execution, Base64 encoding, hex-string obfuscation, and scheduled jobs. It targets , , and uses unique identifiers for each infected machine. The stealer's sophistication is evident in its use of Windows Cryptography API for and its thorough cleanup process.

External references