216.73.217.98

New 'Chihuahua Stealer' Targets Browser Data and Crypto Wallets

· Published 14/05/2025 13:56 · Modified 21/05/2025 19:56

Export JSON

Essential information

Published
14/05/2025 13:56
Modified
21/05/2025 19:56
Tags
.net 2025-05-14 aes-gcm browser data chihuahua stealer crypto wallets infostealer multi-stage infection powershell
Related entities
2 observables, 14 techniques (mitre), 1 malware

Description

A novel named has been detected, blending standard malware techniques with advanced features. This .NET-based malware employs a multi-stage script infection process, utilizing Base64 encoding, hex-string obfuscation, and scheduled tasks for persistence. It targets and cryptocurrency wallet extensions, extracting credentials, cookies, autofill data, browsing history, and payment information. The stolen data is compressed, encrypted using , and exfiltrated to an external server. The malware's sophisticated execution chain includes stealthy loading and a multi-staged payload, making it challenging to detect and analyze.

External references