TROX Stealer: A deep dive into a new Malware as a Service (MaaS) attack campaign · Blog · Sublime Security
ID: 8fc226b7-5a08-59e5-bddc-fa5879166f51
STIX ID: report--8fc226b7-5a08-59e5-bddc-fa5879166f51
Feed Name: Sublime Security Blog
This report provides a deep-dive analysis of the TROX Stealer MaaS infostealer observed in December 2024: attackers sent urgent debt/legal-themed phishing emails that auto-download a Nuitka-compiled multi-stage malware chain (Python executable -> Node.js with embedded WebAssembly) which ultimately retrieves the TROX payload from a public GitHub release and exfiltrates stolen credentials, credit cards, wallets, and session data to GoFile and Telegram; the report documents infrastructure, certificates, IOCs (domains, IPs, file hashes, and malicious sender addresses), and detection signals used to block the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
