logo

ThreatLabz

ID: 1e0067b6-eb19-5d74-9be2-4d3f073baa6f

STIX ID: report--1e0067b6-eb19-5d74-9be2-4d3f073baa6f

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report documents analysis of a Windows backdoor/infostealer that persists via the Startup folder and collects sensitive data through multiple modules: a clipboard clipper (clippa.dan), browser credential/cookie stealers (cdck.bin, bdck.bin targeting Chrome and Yandex), a keylogger (Kebba.dan), and a grabber that exfiltrates documents (grb.bin). The analysis lists artifacts, filesystem paths, a configuration file (Winkeyjet.ini) containing device and C2 information, and notes decoy dropped files used by the malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.