logo

Fileless Stealer and PureRAT Raid Browser Passwords, Telegram Sessions, and Crypto Wallets

ID: 025936ca-2f98-5d44-be1f-6f98dec54778

STIX ID: report--025936ca-2f98-5d44-be1f-6f98dec54778

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

This report describes a sophisticated, active campaign in which operators maintained a WebDAV-backed "malware delivery lab" and used AI-assisted lure generation and QA pipelines to deliver fileless stealers and a modular PureRAT backdoor; the operation targeted browser credentials, Telegram sessions, desktop wallets, and other financial artifacts, leveraged multiple CVE-based hijack vectors and LOLBin execution, and produced substantial telemetry and IOCs tied primarily to Mexican users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.