MaaS VIP Keylogger Campaign Uses Steganography to Steal Credentials at Scale
ID: 6697e527-7a9a-5200-ba89-e9faeeb12342
STIX ID: report--6697e527-7a9a-5200-ba89-e9faeeb12342
Feed Name: GBHackers
Threat Score
A large-scale spear-phishing campaign distributes a VIP Keylogger (MaaS) via fraudulent purchase-order lures and RAR-attached executables; the malware employs steganography and in-memory execution (process hollowing, AMSI/ETW bypass) to steal credentials, cookies, and payment data from 40+ Chromium-based browsers and various email/communication clients, exfiltrating data via SMTP, FTP, Telegram, Discord, and web POSTs, with several sample hashes and sender metadata provided as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
