logo

TinyLoader Malware: Crypto Theft & C2 Infrastructure

ID: 570bea47-6663-5c68-b6df-0ff98bcc975e

STIX ID: report--570bea47-6663-5c68-b6df-0ff98bcc975e

Feed Name: Hunt.io Blog

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report investigates an active TinyLoader malware campaign that operates from servers in Latvia, the UK, and the Netherlands to deliver credential- and crypto-stealing payloads (RedLine Stealer) and remote access trojans (DCRat). The analysis documents initial discovery from suspicious IP activity, confirms a TinyLoader C2 login panel, maps additional infrastructure, describes TTPs (USB and network spread, registry persistence, fake shortcuts, clipboard monitoring and cryptocurrency address replacement), provides captured samples and IOCs (notable IPs and filenames), and offers mitigations to detect and block the operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.