216.73.217.22

VILSA STEALER

· Published 07/10/2024 08:48 · Modified 07/10/2024 09:03

Export JSON

Essential information

Published
07/10/2024 08:48
Modified
07/10/2024 09:03
Tags
2024-10-07 anti-analysis browser credentials cryptocurrency data theft exfiltration persistence vilsa stealer
Related entities
3 observables, 17 techniques (mitre), 2 malware

Description

A new malware called has emerged on GitHub, notable for its speed and efficiency in extracting sensitive data. This sophisticated tool targets , tokens, and various application data. It supports major browsers and over 40 crypto wallets, using Python as its programming language. The malware employs encryption to mask its runtime behavior and includes features for , , and anti-VM detection. It utilizes the GoFile API for data and incorporates additional malware like hvnc.py for remote access. The threat actor uses a specific URL for uploading stolen data to a remote server, which is similar to the 1312 Stealer. The malware's capabilities include bypassing UAC, adding system exclusions to Windows Defender, and stealing a wide range of sensitive information.

External references