Chasing Eddies: New Rust-based InfoStealer used in CAPTCHA campaigns
ID: 5311fb71-838c-5d33-8640-3f04f701ad47
STIX ID: report--5311fb71-838c-5d33-8640-3f04f701ad47
Feed Name: Elastic Security Labs
Elastic Security Labs identified EDDIESTEALER, a Rust-implemented infostealer distributed through fake CAPTCHA pages that trick victims into executing a PowerShell loader; the malware retrieves a task list from C2, targets browser data, password managers, FTP clients, messaging apps, and numerous cryptocurrency wallet files, and exfiltrates each completed task in separate AES-encrypted HTTP POST requests. The report includes detailed static/dynamic analysis (string/API obfuscation, custom WinAPI resolution, mutex naming, sandbox checks, self-deletion via NTFS ADS), Chromium memory extraction techniques, configuration and C2 message formats, detection guidance, and a set of IOCs (hashes, domains, IPs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
