January 2025 Infostealer Trend Report
ID: 863a1ca6-c1d9-5b32-8b09-1b7abecba54b
STIX ID: report--863a1ca6-c1d9-5b32-8b09-1b7abecba54b
Feed Name: ASEC
AhnLab's January 2025 ATIP report documents an active Infostealer campaign distributing malware disguised as cracks via SEO-poisoning and posts on legitimate sites (e.g., GitHub), highlighting LummaC2 as the dominant family and a resurgence of ACRStealer (using Google Docs as C2). The report notes a DLL side‑loading trend with abnormally large DLL payloads to hinder detection, provides MD5 hashes and a distribution URL as IoCs, and explains automated collection/analysis and ATIP real-time IOC blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
