logo

'Chaes' Infostealer Code Contains Hidden Threat Hunter Love Notes

ID: 42b1ea44-2184-5c84-82a2-774da48532c6

STIX ID: report--42b1ea44-2184-5c84-82a2-774da48532c6

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-01-18

Date Updated: 2026-04-21

Author: Becky Bracken, Editor, Dark Reading

...
...

Analysis of Chaes 4.1 reveals an active infostealer campaign that embeds ASCII art and developer messages in its code; the latest campaign uses Portuguese-language phishing lures directing victims to a spoofed TotalAV site that forces a password prompt to deliver an MSI installer. Researchers also observed improvements in the Chaes framework—particularly the Chronod module that intercepts browser activity—and noted the developers left explicit acknowledgements to security researchers within the malware code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.