Account Credential-Stealing Malware Detected by AhnLab MDS (Web Browsers, Email, FTP)
ID: c434a684-a133-58a1-bd32-761e07755fc5
STIX ID: report--c434a684-a133-58a1-bd32-761e07755fc5
Feed Name: ASEC
Threat Score
This AhnLab technical report documents how infostealer malware (e.g., AgentTesla, Lokibot) and custom tools used by APT groups (Andariel, Kimsuky) extract stored account credentials from browsers, email and FTP clients, outlining the operational risk of credential theft and demonstrating how AhnLab MDS’s sandbox-based behavioral analysis detects and alerts on these information-exfiltration behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
