logo

Warning Against Infostealer Disguised as Installer

ID: 72709f7e-ac3b-599b-8258-e9a1864925f4

STIX ID: report--72709f7e-ac3b-599b-8258-e9a1864925f4

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-03-21

Date Updated: 2026-04-26

Author: KDH

...
...

AhnLab describes an active mass-distribution campaign of the StealC infostealer masquerading as installers or cracked software, delivered via platforms like Discord, GitHub, Dropbox and Mega. The malware downloads a PNG with embedded payload data, reconstructs and executes shellcode that loads an AutoIt process, and uses advanced evasion techniques (filename checks, manual ntdll mapping, Heaven’s Gate, process injection). The report includes multiple MD5 hashes, C2 IPs/URLs, ties to Vidar-like samples sharing infrastructure, and recommends avoiding execution of untrusted installers and verifying official download sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.