216.73.216.6

New Stealer on the Horizon

· Published 23/04/2025 16:01 · Modified 23/04/2025 22:58

Export JSON

Essential information

Published
23/04/2025 16:01
Modified
23/04/2025 22:58
Tags
2025-04-23 c2 communication cryptocurrency data harvesting evasion techniques information stealer spear-phishing svcstealer
Related entities
4 observables, 10 techniques (mitre), 1 malware

Description

2025 is a novel delivered through spear phishing email attachments. It harvests sensitive data including machine information, installed software, user credentials, wallets, and browser data. The malware creates a unique folder, terminates specific processes, and collects data from various sources. It compresses the gathered information, establishes a connection with a C2 server, and uploads the data. The malware can also capture screenshots and potentially download additional payloads. It employs by deleting traces and ensuring only one instance runs on the victim's machine. The threat actors behind could potentially act as initial access brokers, selling the gathered information on underground forums and criminal marketplaces.

External references