logo

New NWHStealer Delivery Chain Uses Bun Loader, Anti-VM Checks, and Encrypted C2

ID: b2a05f4f-7265-59a8-93f8-ead2be07cb40

STIX ID: report--b2a05f4f-7265-59a8-93f8-ead2be07cb40

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Tushar Subhra Dutta

...
...

NWHStealer is a resurfaced Rust-based Windows information stealer distributed via malicious ZIPs masquerading as game trainers or cracked software and using the Bun JavaScript runtime to load encrypted, in-memory payloads; it performs anti-VM checks, harvests browser data, passwords, crypto wallets, targets apps like Discord and Steam, persists via scheduled tasks, and uses encrypted C2 infrastructure with fallback loaders. The report includes multiple domains and SHA-256 hashes as IoCs and recommends downloading only from verified sources and verifying signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.