216.73.216.6

Ande Loader Leads to 0bj3ctivity Stealer Infection

· Published 12/08/2024 11:26 · Modified 12/08/2024 11:42

Export JSON

Essential information

Published
12/08/2024 11:26
Modified
12/08/2024 11:42
Tags
0bj3ctivity stealer 2024-08-12 ande loader infection loader malware obfuscation phishing stealer
Related entities
2 observables, 20 techniques (mitre), 2 malware

Description

In July 2024, eSentire's Threat Response Unit observed a attack leading to a . The attack involved a malicious JavaScript file that retrieved and executed and the . created persistence, downloaded additional payloads, and performed process injection. The exfiltrated data from various browsers and messengers to Telegram, servers, or SMTP, including credentials, credit card information, and system details. The attack utilized , anti-analysis techniques, and a multi-stage delivery mechanism to evade detection.

External references