X-VPN Installer Hijacked to Spread STX RAT Malware
ID: cd15a4ea-9fe3-5ec6-859a-98dd4cb59000
STIX ID: report--cd15a4ea-9fe3-5ec6-859a-98dd4cb59000
Feed Name: securityonline.info
A month-long supply-chain operation trojanized installers for cryptocurrency trading tools and ultimately an X-VPN package used by millions; a malicious CRYPTBASE.dll sideloaded STX RAT into memory to steal credentials and provide remote access. The campaign was hosted via a Bitbucket repo and used infrastructure tied to supp0v3.com, and X-VPN released a patch (version 77.5.3) to mitigate the DLL sideloading (CWE-427) vulnerability—users who installed from unofficial sources are at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
