216.73.216.6

Powerful MaaS On the Prowl for Credentials and Crypto Assets

· Published 17/07/2025 19:39 · Modified 17/07/2025 20:26

Export JSON

Essential information

Published
17/07/2025 19:39
Modified
17/07/2025 20:26
Tags
2025-07-17 browser injection credential-theft cryptocurrency data exfiltration evasion techniques infostealer katz stealer maas
Related entities
31 observables, 1 malware

Description

is a sophisticated marketed as Malware-as-a-Service (), launched in early 2025. It features robust credential and data theft capabilities, along with modern evasion and anti-analysis techniques. The stealer targets a wide range of personal and sensitive information, including passwords, keys, and browser session data. Operated through a web-based management panel, allows affiliates to generate custom payloads and manage stolen data. Its infection chain involves obfuscated JavaScript droppers, steganography, and process hollowing techniques. The malware focuses heavily on browser data theft and wallet targeting, with the ability to bypass some browser security measures.

External references