logo

New Infostealer Campaign Targets Users via Spoofed Software Installers

ID: 8e1024f7-dd24-55d2-b487-da95f000a29d

STIX ID: report--8e1024f7-dd24-55d2-b487-da95f000a29d

Feed Name: VirusTotal Blog

Threat Score
74/100

Date Published: 2026-01-16

Date Updated: 2026-05-01

Author: Joseliyo Sánchez

...
...

VirusTotal researchers tracked an active campaign (Jan 11–15, 2026) that distributes ZIPs named to resemble legitimate software and contains a trusted executable plus a malicious CoreMessaging.dll which is executed via DLL sideloading; the DLL drops secondary infostealers that exfiltrate credentials and crypto-wallet data. The report provides concrete IOCs (primary behash 4acaac53..., secondary behash 5ddb6041..., many SHA256s), distinctive metadata signature strings and unusual export names for hunting, and points to VirusTotal relations/execution_parents for pivoting and further retrieval of related samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.