“PupkinStealer” – New .NET Malware Harvests Browser Credentials and Sends Them via Telegram
ID: 814e825f-8598-5938-a637-428edd02553e
STIX ID: report--814e825f-8598-5938-a637-428edd02553e
Feed Name: Cyber Press
PupkinStealer is a lightweight C#/.NET information stealer that extracts Chromium browser passwords, copies Telegram and Discord session tokens, collects selected desktop files and a screenshot, packages artifacts into a ZIP (with victim metadata), and exfiltrates the archive using the Telegram Bot API; the report provides IOCs (file hashes, Telegram bot token and exfiltration URL, file paths) and recommends EDR, outbound Telegram traffic monitoring, application whitelisting, and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
