PurpleWave—A New Infostealer from Russia
ID: 301fa34f-ca9b-5f55-b11c-e73e6d0c8b8d
STIX ID: report--301fa34f-ca9b-5f55-b11c-e73e6d0c8b8d
Feed Name: Zscaler Security Research Blog
PurpleWave is an actively available C++ infostealer sold on Russian cybercrime forums that silently installs on Windows systems, harvests browser credentials, cookies, cards, autofill data, screenshots, Telegram and Steam session files, Electrum wallet data, and system information, and communicates with live C2 servers to upload stolen data and download additional modules; the report provides detailed technical analysis, MITRE ATT&CK mappings, sandbox coverage, and multiple IOCs (file hashes and C2 URLs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
