216.73.217.22

CoinLurker: The Stealer Powering the Next Generation of Fake Updates

· Published 17/12/2024 09:57 · Modified 17/12/2024 10:06

Export JSON

Essential information

Published
17/12/2024 09:57
Modified
17/12/2024 10:06
Tags
2024-12-17 coinlurker cryptocurrency
Related entities
50 observables, 1 intrusion sets (apt), 14 techniques (mitre), 1 malware, 1 others

Description

is a sophisticated stealer designed to exfiltrate data while evading detection. Written in Go, it employs advanced obfuscation and anti-analysis techniques, making it highly effective in modern cyberattacks. The malware is delivered through fake update campaigns, leveraging deceptive entry points that exploit user trust. It uses Microsoft Edge Webview2 as a stager and employs a multi-stage chain involving Binance Smart Contracts and Bitbucket repositories to conceal its payload. targets wallets and financial applications, systematically enumerating directories to access sensitive user data. Its layered injection tactics and obfuscated functions make it challenging for analysts to reverse-engineer its logic.

External references