216.73.216.6

Analysis of Astral Stealer

· Published 31/01/2025 19:20 · Modified 31/01/2025 20:07

Export JSON

Essential information

Published
31/01/2025 19:20
Modified
31/01/2025 20:07
Tags
2025-01-31 astral stealer browser injection cryptocurrency data exfiltration discord injection information theft stealer
Related entities
3 observables, 33 techniques (mitre), 1 malware

Description

v1.8 is a powerful malware tool coded in Python, C#, and JavaScript, designed for data theft and crypto wallet exploitation. It targets gaming accounts, browser credentials, and wallets while employing anti-debugging and VM bypass techniques. The offers advanced features like viewing backup codes, auto-changing email, and an anti-delete system. It uses a customizable builder with a user-friendly interface. Key capabilities include fake error generation, background operation, startup persistence, anti-VM measures, browser extension injection, , process termination, and wallet data extraction. It can bypass security tools, capture system information, disable Windows Defender, and exfiltrate data via webhooks. The malware's public availability on GitHub and its continuous development by multiple contributors pose significant threats to individuals and organizations.

External references