New 'Chihuahua Stealer' Targets Browser Data and Crypto Wallets
Essential information
- Published
- 14/05/2025 13:56
- Modified
- 21/05/2025 19:56
- Tags
- .net 2025-05-14 aes-gcm browser data chihuahua stealer crypto wallets infostealer multi-stage infection powershell
- Related entities
- 2 observables, 14 techniques (mitre), 1 malware
Description
A novel infostealer named Chihuahua Stealer has been detected, blending standard malware techniques with advanced features. This .NET-based malware employs a multi-stage PowerShell script infection process, utilizing Base64 encoding, hex-string obfuscation, and scheduled tasks for persistence. It targets browser data and cryptocurrency wallet extensions, extracting credentials, cookies, autofill data, browsing history, and payment information. The stolen data is compressed, encrypted using AES-GCM, and exfiltrated to an external server. The malware's sophisticated execution chain includes stealthy loading and a multi-staged payload, making it challenging to detect and analyze.