Death Stealer forked from PowerShell Token Grabber
Essential information
- Published
- 05/07/2024 08:14
- Modified
- 05/07/2024 08:24
- Tags
- 2024-07-05 kematian stealer powershell token grabber stealer
- Related entities
- 14 techniques (mitre), 1 malware
Description
The report analyzes Kematian Stealer, a sophisticated PowerShell-based malware that exfiltrates sensitive data from infected systems. It is a forked version of PowerShell Token Grabber, with added capabilities like GUI builder, anti-analysis features, and stealing WiFi passwords, screenshots, and session data from messaging, gaming, VPN clients, and more. The malware persists through scheduled tasks, collects system information, steals browser data, and exfiltrates it via a Discord webhook.