logo

Stumbling Upon XehookStealer C2 Instances

ID: 3fd6505c-5209-5a0d-a1e4-55a16920b7a1

STIX ID: report--3fd6505c-5209-5a0d-a1e4-55a16920b7a1

Feed Name: Censys Blog

Threat Score
65/100

Date Published: 2024-07-26

Date Updated: 2026-04-27

Author: Ivonne Francia; Aidan Holland; Senior Security Researcher

...
...

Aidan Holland of Censys re-evaluated C2 fingerprints and identified infrastructure linked to Agniane Stealer and Xehook Stealer: 11 hosts sharing a distinctive favicon (MD5 63e939086ab01ddefcef0cfd052b7368), HTTP body strings referencing https://t.me/agniane and xehook.stealer, an exposed non-Cloudflare host (193.149.190.2), and common /login endpoints; the report includes a captured login screenshot and pivots to provide indicators for threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.