Server-Side Infostealers: How Initial Access Broker Pryx is Revolutionizing Infostealers
ID: 50fa5345-c536-5258-ae69-60d9e156f10a
STIX ID: report--50fa5345-c536-5258-ae69-60d9e156f10a
Feed Name: infostealers.com
This report summarizes an interview with 'Pryx', an admin of the Hellcat ransomware group, who describes a server-side infostealer model that establishes Tor onion services on compromised hosts and allows attackers to remotely scrape credentials, tokens, and files; Pryx outlines modular hybrid tactics (lightweight client payloads + server-side harvesting), advanced techniques such as token hijacking and server-side AiTM, and a monetization model selling pre-compromised servers to ransomware and fraud operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
