216.73.217.22

YUNIT STEALER

· Published 07/10/2024 10:46 · Modified 07/10/2024 13:03

Export JSON

Essential information

Published
07/10/2024 10:46
Modified
07/10/2024 13:03
Tags
2024-10-07 credential extraction cryptocurrency data theft gaming yunit stealer
Related entities
8 techniques (mitre), 1 malware, 1 others

Description

is a sophisticated malware targeting sensitive user data through credential theft and system manipulation. It employs advanced evasion techniques to bypass security measures, maintaining persistence on compromised systems. The malware performs comprehensive data extraction, including system information, browser data, and wallets. It achieves persistence through registry modifications, scheduled tasks, and Windows Defender exclusions. Data exfiltration occurs via Telegram and Discord webhooks. The developer is likely a French speaker with ties to platforms. The malware incorporates system checks, file management, and extraction of sensitive data like credentials and cookies. It uses obfuscation and geofencing capabilities to avoid detection and selectively operate based on geographic location.

External references