The Unknown Stealers: What’s Hidden Below the Radar
ID: 96608a97-c263-5338-b3af-8b0baeef393c
STIX ID: report--96608a97-c263-5338-b3af-8b0baeef393c
Feed Name: SOCRadar Blog
This report examines the evolving infostealer economy and provides a technical breakdown of Void Stealer — a C++ grab-and-go infostealer active in multiple affiliate campaigns that collects browser credentials, cookies, crypto wallets, desktop wallet files, messaging tokens, and system fingerprints. Void uses advanced evasion (runtime syscall/API resolution, XOR-encrypted config, mutex-based single-instance, and Steam-profile-based C2 resolution), uploads JSON/Base64-encoded logs to intermediate C2s with Telegram notification integration, and feeds stolen data into underground log markets that directly enable account takeover, initial access sales, and ransomware chains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
