Breaking into the Bandit Stealer Malware Infrastructure
ID: af1c1da2-a51e-5180-b509-757b5206f91a
STIX ID: report--af1c1da2-a51e-5180-b509-757b5206f91a
Feed Name: CloudSEK Blog
CloudSEK analyzes Bandit Stealer, a Go-based information stealer distributed via YouTube, uncovering at least 14 recently active web panels with misconfigurations exposing builder outputs and client logs. The malware employs anti-debugging and sandbox checks, kills analysis tools, persists via autorun, targets numerous browsers and 25+ cryptocurrency wallets, and exfiltrates system, credential, cookie, and screenshot data to a Telegram C2; the report includes IoCs (three MD5 hashes, IP 149.154.167.220, and a YouTube URL) and details TTPs aligned with known open-source components (EMPYREAN blacklist).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
