logo

Hackers Selling GlorySprout Malware with Anti-VM Features in underground Fourm for $300

ID: baef7278-71a0-53bc-b2c9-84ef53f32dec

STIX ID: report--baef7278-71a0-53bc-b2c9-84ef53f32dec

Feed Name: GBHackers

Threat Score
68/100

Date Published: 2024-03-20

Date Updated: 2026-04-22

Author: Balaji

...
...

GlorySprout is an information-stealer marketed on underground forums and reported as a clone of Taurus Stealer; the report provides technical analysis showing API-hashing/obfuscation, scheduled-task persistence, predictable RC4 key usage for C2 communications over port 80, server-side decryption of stolen credentials, and SQL-based server artifacts. The analysis notes distribution and leaked/cracked source circulation, highlights differences from Taurus (no DLL downloads and lack of anti-VM), and lists observable IOCs and behavior useful for detection and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.