HANNIBAL Stealer: A Rebranded Threat Born from Sharp and TX Lineage
Essential information
- Published
- 30/04/2025 08:20
- Modified
- 30/04/2025 08:58
- Tags
- 2025-04-26 2025-04-30 browser data theft c2 panel cryptocurrency data exfiltration geofencing hannibal stealer information stealer rebranded malware sharp stealer telegram channels tx stealer vpn credential theft vpn credentials
- Related entities
- 4 observables, 1 intrusion sets (apt), 13 techniques (mitre), 3 malware
Description
The Hannibal Stealer is a sophisticated information stealer targeting Chromium and Gecko-based browsers, developed in C# and operating on the .NET Framework. It bypasses Chrome Cookie V20 protection and steals data from cryptocurrency wallets, FTP clients, VPNs, and messaging apps. The malware performs system profiling, captures screenshots, and exfiltrates targeted files. It includes a crypto clipper module and is controlled via a dedicated C2 user panel. Advertised on various forums, it employs geofencing, domain-matching, and comprehensive data theft techniques. The stealer is likely a rebranded version of earlier SHARP and TX Stealers, with minimal innovation beyond updated communication methods.