Rilide - An Information Stealing Browser Extension
ID: 744a835c-2301-58b6-ac92-556c49fddf0f
STIX ID: report--744a835c-2301-58b6-ac92-556c49fddf0f
Feed Name: Pulsedive Blog
Rilide is an information-stealing malware masquerading as a browser extension (often impersonating Google Drive) that targets Chromium-based browsers to capture screenshots, log credentials (including cryptocurrency wallets), manipulate web pages/emails, and exfiltrate data to a C2 resolved via blockchain-based dead drops; the report provides a multi-stage PowerShell dropper analysis, file/manifest contents, network IoCs, MITRE ATT&CK mappings, and mitigations including extension management and PowerShell logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
