NWHStealer Delivery Chain Adds Anti-VM Checks and Encrypted C2 Traffic
ID: c4ce4bcb-9213-50b2-b8fe-1b853be66b08
STIX ID: report--c4ce4bcb-9213-50b2-b8fe-1b853be66b08
Feed Name: Cyber Press
Threat Score
This report describes active campaigns delivering NWHStealer, a Rust-built info-stealer that exfiltrates browser credentials and crypto-wallet data; actors are now packaging obfuscated JavaScript with the Bun runtime (and a fallback self-injection loader) to evade analysis, perform anti-VM checks, and establish encrypted C2 communications — several C2 domains are provided as indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
