logo

KuinaExtractor Uses Telegram Exfiltration, UAC Bypass, and Sandbox Detection for Stealth

ID: 0836424b-4e2c-5add-a24e-729d5123e1df

STIX ID: report--0836424b-4e2c-5add-a24e-729d5123e1df

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Tushar Subhra Dutta

...
...

KuinaExtractor (later rebranded k0to) is a Rust-based infostealer tracked over six months that steals browser data, cryptocurrency wallets, and service credentials; it progressively added evasion (XOR string obfuscation, custom certificate roots, sandbox checks), multiple UAC bypass techniques, and moved exfiltration from Discord webhooks to a Telegram bot, with researchers linking samples via shared mutexes, build paths, and Telegram handles and publishing IoCs and YARA rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.