Stumbling Upon XehookStealer C2 Instances
ID: 3fd6505c-5209-5a0d-a1e4-55a16920b7a1
STIX ID: report--3fd6505c-5209-5a0d-a1e4-55a16920b7a1
Feed Name: Censys Blog
Date Published: 2024-07-26
Date Updated: 2026-04-27
Author: Ivonne Francia; Aidan Holland; Senior Security Researcher
Aidan Holland of Censys re-evaluated C2 fingerprints and identified infrastructure linked to Agniane Stealer and Xehook Stealer: 11 hosts sharing a distinctive favicon (MD5 63e939086ab01ddefcef0cfd052b7368), HTTP body strings referencing https://t.me/agniane and xehook.stealer, an exposed non-Cloudflare host (193.149.190.2), and common /login endpoints; the report includes a captured login screenshot and pivots to provide indicators for threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
