Warning Against Infostealer Disguised as Installer
ID: 72709f7e-ac3b-599b-8258-e9a1864925f4
STIX ID: report--72709f7e-ac3b-599b-8258-e9a1864925f4
Feed Name: ASEC
AhnLab describes an active mass-distribution campaign of the StealC infostealer masquerading as installers or cracked software, delivered via platforms like Discord, GitHub, Dropbox and Mega. The malware downloads a PNG with embedded payload data, reconstructs and executes shellcode that loads an AutoIt process, and uses advanced evasion techniques (filename checks, manual ntdll mapping, Heaven’s Gate, process injection). The report includes multiple MD5 hashes, C2 IPs/URLs, ties to Vidar-like samples sharing infrastructure, and recommends avoiding execution of untrusted installers and verifying official download sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
