logo

Chasing Eddies: New Rust-based InfoStealer used in CAPTCHA campaigns

ID: 5311fb71-838c-5d33-8640-3f04f701ad47

STIX ID: report--5311fb71-838c-5d33-8640-3f04f701ad47

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2025-05-30

Date Updated: 2026-04-27

...
...

Elastic Security Labs identified EDDIESTEALER, a Rust-implemented infostealer distributed through fake CAPTCHA pages that trick victims into executing a PowerShell loader; the malware retrieves a task list from C2, targets browser data, password managers, FTP clients, messaging apps, and numerous cryptocurrency wallet files, and exfiltrates each completed task in separate AES-encrypted HTTP POST requests. The report includes detailed static/dynamic analysis (string/API obfuscation, custom WinAPI resolution, mutex naming, sandbox checks, self-deletion via NTFS ADS), Chromium memory extraction techniques, configuration and C2 message formats, detection guidance, and a set of IOCs (hashes, domains, IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.