logo

Following the Trail - Meduza Stealer

ID: 795fc737-b043-5a28-9cb3-9b1b07f001d8

STIX ID: report--795fc737-b043-5a28-9cb3-9b1b07f001d8

Feed Name: IntelInsights (Substack)

Threat Score
68/100

Date Published: 2024-12-08

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

The report documents an investigation into Meduza stealer infrastructure starting from an open-directory distribution server (89.23.100.74) and pivots using service/HTTP fingerprints to identify additional potential distribution hosts and 11 C2 servers via a shared HTTP body hash. It highlights hosting concentrations in AS56694 (Smart Ape LLC) and AS210644 (Aeza International Ltd), shares search queries used for discovery, and provides explicit IOCs (IP addresses and a response body hash) to aid defenders in hunting and blocking related infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.