logo

CrackedCantil: A Malware Symphony Breakdown

ID: 11330a51-9017-5768-8b43-cf833e8c6636

STIX ID: report--11330a51-9017-5768-8b43-cf833e8c6636

Feed Name: infostealers.com

Threat Score
75/100

Date Published: 2024-02-04

Date Updated: 2026-04-28

Author: InfoStealers

...
...

This report details the “CrackedCantil” infection chain delivered via cracked software: PrivateLoader and Smoke load multiple payloads that perform credential theft (Lumma, RedLine, RisePro, Amadey, Stealc), proxying (Socks5Systemz), cryptomining, and ultimately STOP/DJVU ransomware encryption; the analysis includes sandbox behavior, process trees, network C2 traffic, IOCs (file hashes, IPs, URLs), and mapped MITRE techniques to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.