Cybercriminals Impersonate Malwarebytes to Steal User Credentials
ID: 6e90294a-6ab0-5105-854e-ab0a98828ab2
STIX ID: report--6e90294a-6ab0-5105-854e-ab0a98828ab2
Feed Name: GBHackers
A short, well-structured campaign (2026-01-11 to 2026-01-15) impersonated MalwareBytes by distributing ZIP archives named like `malwarebytes-windows-github-io-X.X.X.zip` that include a legitimate EXE and a malicious CoreMessaging.dll which achieves execution via DLL sideloading; final-stage infostealers then harvest credentials and crypto‑wallet data. Stable indicators include behash `4acaac53c8340a8c236c91e68244e6cb` (initial ZIPs), final-stage behash `5ddb604194329c1f182d7ba74f6f5946`, TXT pivot files (e.g., `gitconfig.com.txt`, `Agreement_About.txt`), and distinctive DLL metadata/exports useful for VT and EDR hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
