216.73.217.98

LeakyInjector and LeakyStealer Duo Hunts For Crypto and Browser History

· Published 07/11/2025 09:02 · Modified 07/11/2025 09:33

Export JSON

Essential information

Published
07/11/2025 09:02
Modified
07/11/2025 09:33
Tags
2025-11-07 browser-history cryptocurrency data exfiltration injection leakyinjector leakystealer persistence polymorphic two-stage
Related entities
5 observables, 2 malware

Description

A new malware named and has been identified, targeting wallets and browser history. uses low-level APIs for to avoid detection and injects into explorer.exe. implements a engine to modify its memory area at runtime. Both stages were signed with valid Extended Validation certificates. The malware performs reconnaissance on infected machines, targeting multiple crypto wallets, including browser extensions, and searches for browser history files from various browsers. It establishes through registry manipulation and beacons to the C2 server at regular intervals. The malware exfiltrates sensitive data and can execute additional commands received from the C2 server.

External references