Fake Proton VPN Sites and Gaming Mods Spread NWHStealer in New Windows Malware Campaign
ID: 6f247ca9-f811-5147-9272-6beef2268ee6
STIX ID: report--6f247ca9-f811-5147-9272-6beef2268ee6
Feed Name: cybersecurityNews.com
Malwarebytes researchers identified NWHStealer, an information-stealing Windows malware campaign that spreads through fake VPN websites, code-hosting and file-sharing mirrors, gaming mods, YouTube links, and compromised web hosting. The campaign uses layered loaders (MSI/Node.js wrappers), DLL hijacking and process hollowing to inject payloads into legitimate processes (e.g., RegAsm.exe), employs UAC bypass (CMSTP) and Defender exclusions for persistence, and exfiltrates browser credentials and cryptocurrency wallet data to C2 servers with a Telegram-based dead-drop fallback.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
