New Infostealer Trojan uses Fiddler Proxy & Json.NET
ID: 118bd28e-f491-53d5-adf7-52700a98ea00
STIX ID: report--118bd28e-f491-53d5-adf7-52700a98ea00
Feed Name: Zscaler Security Research Blog
**Executive Summary:** Zscaler ThreatLabZ discovered a .NET-based Infostealer Trojan (installer named with double-extension like curp.pdf.exe) actively targeting Banamex customers in Mexico and capable of updating its C2 configuration to add further financial targets; the malware deploys FiddlerCore and Json.NET to intercept HTTP/HTTPS traffic, perform domain-to-IP hijacking to serve phishing sites, and periodically refreshes C2 lists every 10 minutes. The report includes technical behavior, persistence differences by OS version, sample C2/config format, and multiple MD5 IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
