CoralRaider targets victims’ data and social media accounts
ID: de3818e5-4a22-5524-a65a-2cf75b051989
STIX ID: report--de3818e5-4a22-5524-a65a-2cf75b051989
Feed Name: infostealers.com
Cisco Talos documents 'CoralRaider', a financially motivated threat actor likely based in Vietnam that has used malicious Windows shortcut files to deliver an LNK→HTA→VBScript→PowerShell chain to deploy RotBot (a QuasarRAT variant) and the XClient stealer; the actors exfiltrate browser credentials, social-media ad/business account data, and financial information via Telegram bots and use living-off-the-land binaries and other evasion techniques in a multi-country campaign across Asia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
