'Chaes' Infostealer Code Contains Hidden Threat Hunter Love Notes
ID: 42b1ea44-2184-5c84-82a2-774da48532c6
STIX ID: report--42b1ea44-2184-5c84-82a2-774da48532c6
Feed Name: Dark Reading
Analysis of Chaes 4.1 reveals an active infostealer campaign that embeds ASCII art and developer messages in its code; the latest campaign uses Portuguese-language phishing lures directing victims to a spoofed TotalAV site that forces a password prompt to deliver an MSI installer. Researchers also observed improvements in the Chaes framework—particularly the Chronod module that intercepts browser activity—and noted the developers left explicit acknowledgements to security researchers within the malware code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
