logo

Account Credential-Stealing Malware Detected by AhnLab MDS (Web Browsers, Email, FTP)

ID: c434a684-a133-58a1-bd32-761e07755fc5

STIX ID: report--c434a684-a133-58a1-bd32-761e07755fc5

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-02-01

Date Updated: 2026-04-26

Author: Sanseo

...
...

This AhnLab technical report documents how infostealer malware (e.g., AgentTesla, Lokibot) and custom tools used by APT groups (Andariel, Kimsuky) extract stored account credentials from browsers, email and FTP clients, outlining the operational risk of credential theft and demonstrating how AhnLab MDS’s sandbox-based behavioral analysis detects and alerts on these information-exfiltration behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.