A Malware that Mimics Pirated Software Sites
ID: 21ff10ef-f739-5d4a-8a28-925c1b19163c
STIX ID: report--21ff10ef-f739-5d4a-8a28-925c1b19163c
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz analyzed active campaigns that distribute info-stealer malware by luring users to fake shareware/pirated-software sites which perform multiple redirects to malicious hosts; two detailed cases show a padded/encoded loader that stages a RedLine Stealer via reversed JPG-to-DLL delivery and a Themida-packed RecordBreaker sample that harvests browser credentials, cookies, crypto-wallet extensions, screenshots, and system/software metadata. The report lists numerous malicious IPs and fake download/redirect domains, demonstrates anti-VM/anti-debug and packing techniques used to evade detection, and provides basic mitigations (avoid pirated software, block password-protected archives, do not save browser credentials).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
