logo

CoralRaider attacks use CDN cache to push info-stealer malware

ID: 8f4c0c4a-2e3e-5d7e-9c0a-7522d4889ef9

STIX ID: report--8f4c0c4a-2e3e-5d7e-9c0a-7522d4889ef9

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-04-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cisco Talos attributes an ongoing CoralRaider campaign to a financially motivated actor using CDN cache-hosted HTA/PowerShell chains delivered via malicious LNK archives to deploy info-stealers (Cryptbot, LummaC2, Rhadamanthys). The campaign uses obfuscation, Defender exclusion modifications, a FoDHelper UAC bypass, and targets victims across multiple countries to steal credentials, financial data, and account cookies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.