Fileless Stealer and PureRAT Raid Browser Passwords, Telegram Sessions, and Crypto Wallets
ID: 025936ca-2f98-5d44-be1f-6f98dec54778
STIX ID: report--025936ca-2f98-5d44-be1f-6f98dec54778
Feed Name: GBHackers
This report describes a sophisticated, active campaign in which operators maintained a WebDAV-backed "malware delivery lab" and used AI-assisted lure generation and QA pipelines to deliver fileless stealers and a modular PureRAT backdoor; the operation targeted browser credentials, Telegram sessions, desktop wallets, and other financial artifacts, leveraged multiple CVE-based hijack vectors and LOLBin execution, and produced substantial telemetry and IOCs tied primarily to Mexican users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
