An Infostealer Searching for « BIP-0039 » Data, (Fri, Nov 22nd)
ID: 299bc007-4517-500a-86c3-3355629f7d3d
STIX ID: report--299bc007-4517-500a-86c3-3355629f7d3d
Feed Name: SANS ISC Diary
**Executive summary:** The report dissects a malicious Python script that installs the 'mnemonic' module to detect BIP‑0039 mnemonic seed phrases (12/16/24 English words) by recursively scanning user files and exfiltrating matches; the author provides code excerpts, the sample SHA256 (737c6c397d182f27f692e2934d2a1235011a41c09e5f8640d21a8fee0c48c632) and notes a VirusTotal detection of 10/64. The malware specifically targets English seed phrases and poses a direct theft risk to cryptocurrency holders despite its relatively simple implementation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
