logo

An Infostealer Searching for « BIP-0039 » Data, (Fri, Nov 22nd)

ID: 299bc007-4517-500a-86c3-3355629f7d3d

STIX ID: report--299bc007-4517-500a-86c3-3355629f7d3d

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2024-11-22

Date Updated: 2026-04-19

...
...

**Executive summary:** The report dissects a malicious Python script that installs the 'mnemonic' module to detect BIP‑0039 mnemonic seed phrases (12/16/24 English words) by recursively scanning user files and exfiltrating matches; the author provides code excerpts, the sample SHA256 (737c6c397d182f27f692e2934d2a1235011a41c09e5f8640d21a8fee0c48c632) and notes a VirusTotal detection of 10/64. The malware specifically targets English seed phrases and poses a direct theft risk to cryptocurrency holders despite its relatively simple implementation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.