Fake ProtonVPN, game mod sites spread NWHStealer in new Windows malware campaign
ID: 1ed5b299-2925-5af1-858b-f1a36af1fa66
STIX ID: report--1ed5b299-2925-5af1-858b-f1a36af1fa66
Feed Name: GBHackers
NWHStealer campaigns are actively distributing an information-stealing trojan by masquerading as legitimate installers (Proton VPN, OhmGraphite, Sidebar Diagnostics, etc.) and hosting payloads across lookalike domains, GitHub/GitLab, MediaFire, SourceForge and YouTube-linked downloads; the malware uses DLL hijacking, process hollowing, in-memory/decrypted loaders, scheduled tasks, CMSTP UAC bypass, and Telegram-based dead drops to persist and exfiltrate AES-CBC–encrypted browser credentials and cryptocurrency wallet data to C2 servers — users should only download from official vendors, verify signatures, and use browser/site protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
