216.73.216.226

Threat Actors are Targeting US Tax-Session with new Tactics of Stealerium-infostealer

· Published 30/04/2025 17:22 · Modified 30/04/2025 21:54

Export JSON

Essential information

Published
30/04/2025 17:22
Modified
30/04/2025 21:54
Tags
2025-04-30 anti-analysis information-stealing powershell process injection stealerium tax-season phishing
Related entities
1 malware, 3 others

Description

Cybercriminals are exploiting the US tax season to deploy malware, targeting citizens through sophisticated phishing campaigns. The attack utilizes deceptive email attachments with malicious LNK files, leading to the execution of scripts and the download of a PyInstaller-packaged executable. This payload injects into mstsc.exe and deploys , an malware that exfiltrates sensitive data from browsers, cryptocurrency wallets, and popular applications. The malware employs techniques, creates a hidden directory, and registers with a command and control server. It steals credentials from various sources, including browsers, gaming platforms, and messaging apps, while also capturing webcam images and Wi-Fi passwords.

External references