216.73.217.80

HANNIBAL Stealer: A Rebranded Threat Born from Sharp and TX Lineage

· Published 30/04/2025 08:20 · Modified 30/04/2025 08:58

Export JSON

Essential information

Published
30/04/2025 08:20
Modified
30/04/2025 08:58
Tags
2025-04-26 2025-04-30 browser data theft c2 panel cryptocurrency data exfiltration geofencing hannibal stealer information stealer rebranded malware sharp stealer telegram channels tx stealer vpn credential theft vpn credentials
Related entities
4 observables, 1 intrusion sets (apt), 13 techniques (mitre), 3 malware

Description

The is a sophisticated targeting Chromium and Gecko-based browsers, developed in C# and operating on the .NET Framework. It bypasses Chrome Cookie V20 protection and steals data from wallets, FTP clients, VPNs, and messaging apps. The malware performs system profiling, captures screenshots, and exfiltrates targeted files. It includes a crypto clipper module and is controlled via a dedicated C2 user panel. Advertised on various forums, it employs , domain-matching, and comprehensive data theft techniques. The stealer is likely a rebranded version of earlier SHARP and TX Stealers, with minimal innovation beyond updated communication methods.

External references