ShinyHunters: Silent Malware as a Service (MaaS)
ID: 8e1d82b6-b98b-5ea9-a90c-4f29fd59d40e
STIX ID: report--8e1d82b6-b98b-5ea9-a90c-4f29fd59d40e
Feed Name: Ransomware ISAC Blog
Date Published: 2026-05-26
Date Updated: 2026-08-21
Author: [email protected] (Ransom-ISAC Research Team)
This report analyzes "Illusion-2.6.5-setup.exe", a packaged deployment of Silent Stealer v2.6.5 distributed via Telegram, detailing its multi-layer obfuscation, extensive credential and session theft (browsers, Discord, Steam, Roblox, Telegram tdata, crypto wallets), integrated RAT capabilities (remote PowerShell, filesystem access, screenshots, live chat), five persistence mechanisms, four UAC bypass methods, and active C2 infrastructure with publicly accessible operator panel and numerous IOCs and KQL detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
