New NWHStealer Delivery Chain Uses Bun Loader, Anti-VM Checks, and Encrypted C2
ID: b2a05f4f-7265-59a8-93f8-ead2be07cb40
STIX ID: report--b2a05f4f-7265-59a8-93f8-ead2be07cb40
Feed Name: cybersecurityNews.com
NWHStealer is a resurfaced Rust-based Windows information stealer distributed via malicious ZIPs masquerading as game trainers or cracked software and using the Bun JavaScript runtime to load encrypted, in-memory payloads; it performs anti-VM checks, harvests browser data, passwords, crypto wallets, targets apps like Discord and Steam, persists via scheduled tasks, and uses encrypted C2 infrastructure with fallback loaders. The report includes multiple domains and SHA-256 hashes as IoCs and recommends downloading only from verified sources and verifying signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
