logo

New MultiloginBot Phishing Campaign

ID: 522955be-2116-5b38-9caa-8149ea4cad00

STIX ID: report--522955be-2116-5b38-9caa-8149ea4cad00

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz describes a live phishing campaign that clones the Multilogin website (domains multilogin-uk.com and multilogin-us.com) to trick users into installing a malicious .NET installer which deploys an info-stealer. The malware creates persistence, collects IP, browser autofill, cookies, and stored credentials (including Firefox via nss3.dll), archives the data to a ZIP and exfiltrates it to a Telegram bot; the report includes MD5 hashes, phishing domains, MITRE ATT&CK mappings, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.