216.73.217.22

Technical Analysis of RiseLoader

· Published 16/12/2024 23:06 · Modified 17/12/2024 10:04

Export JSON

Essential information

Published
16/12/2024 23:06
Modified
17/12/2024 10:04
Tags
2024-12-16 cryptocurrency lumma stealer malware loader riseloader risepro socks5systemz vidar xmrig
Related entities
15 techniques (mitre), 8 malware

Description

, a new family observed in October 2024, implements a custom TCP-based binary network protocol similar to . It uses VMProtect for obfuscation and has been observed dropping malware families like , , , and . The malware collects information about installed applications and browser extensions related to . 's network communication protocol involves exchanging various message types with the C2 server, including system information, payload instructions, and task execution status. The similarities between and suggest they may be developed by the same threat actor, with potentially still in development for future information stealing and anti-analysis features.

External references