logo

ShinyHunters: Silent Malware as a Service (MaaS)

ID: de5c176f-9bee-524f-b37d-a7048774e2f3

STIX ID: report--de5c176f-9bee-524f-b37d-a7048774e2f3

Feed Name: Ransomware ISAC Blog

Threat Score
80/100

Date Published: 2026-05-26

Date Updated: 2026-07-29

Author: [email protected] (Ransom-ISAC Research Team)

...
...

This report analyzes Illusion-2.6.5-setup.exe — a Silent Stealer v2.6.5 build packaged as a fake Electron NSIS installer — detailing extraction steps, three-layer obfuscation, AES-encrypted payloads, active C2 backends, exposed operator panel, extensive IOCs (hashes, domains, IPs, keys), broad credential/session theft (browsers, wallets, Discord, Telegram tdata, Steam, Roblox, TikTok, Minecraft), RAT capabilities (remote PowerShell, filesystem, screenshots, live chat), multiple persistence and UAC bypass methods, and recommended KQL detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.