logo

Felipe, a new infostealer Trojan

ID: 6ca18c7a-d907-502d-ae4e-b8edaba8e96b

STIX ID: report--6ca18c7a-d907-502d-ae4e-b8edaba8e96b

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Felipe infostealer (Windows)**: This report analyzes the Felipe infostealer which installs persistently on Windows (32/64-bit), disables Defender and UAC protections, scrapes process memory and keystrokes to harvest payment card and personal data (using Luhn-style validation), encrypts exfiltrated data with 3DES, and sends it to a remote C2; the analysis includes dropped file paths, persistence mechanisms, memory-dumping methods, sample hashes, and download URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.