Ethereum Malware Loader Targets Portuguese-Speaking Users
ID: 42a5c967-42ab-5425-9931-13e6a777bd49
STIX ID: report--42a5c967-42ab-5425-9931-13e6a777bd49
Feed Name: WatchGuard Secplicity Blog
This WatchGuard Threat Lab analysis describes a sophisticated, modular malware campaign that begins with obfuscated JScript to install a self-contained Node.js runtime, queries an Ethereum smart contract for dynamic configuration, downloads a CAB containing a legitimate signed executable and a malicious SentinelAgentCore.dll used for DLL side-loading, and ultimately deploys a malicious Chromium extension that provides remote-control capabilities and steals cookies, session/local storage, DOM content, screenshots, and keystrokes for targeted domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
